Tony's ramblings on Open Source Software, Life and Photography

evil-underbelly of the Internet

Using Twitter to Hack and Google Bomb

There's a new tactic going on with Twitter. Enterprising young hackers and spammers are using bot programs to scour the web for blog and content management sites that are not locked down very well. Once found, the bot posts a "tweet" on Twitter with a few bits of text from the site's main page, along with a link to the new user account profile the bot has created on the site.

The bot also posts a bit of data in it's "bio" on the new site with various links it's wanting to increase the popularity of in Google. What's even more interesting is that there will generally be several hundred followers of the bot, but the bot follows noone. Are those people who want to make use of the accounts that the bot has rooted out?

Some bots will specifically target certain types of content management software. For instance, I've stumbled on several that will target ExpressionEngine, but others go after Drupal or Wordpress blogs that allow users to register accounts.

In most if not all cases, the users running those website don't even realize they are now host to spam fodder.