Weibo hack attack highlights holes

0 Comment(s)Print E-mail Global Times, July 7, 2011
Adjust font size:

The suspect allegedly behind the widespread distribution of a virus on Sina Weibo has been arrested, according to the Beijing Times on Wednesday, but concerns remain over the security of China's hugely popular microblogging services.

Neither Sina's publicity department nor the Municipal Public Security Bureau would confirm the arrest of the person whose alleged virus infected more than 30,000 Weibo users, including official Sina microblogs, between 8:20 and 9:25 pm on June 28, according to the Legal Mirror.

During the attack, users received private messages titled "income tax exemption threshold is expected to be raised to 4,000 yuan (US$618)," or "sex photos of celebrity actress Fan Bingbing," with a link. If one clicked the links, their accounts automatically posted the same entry repeatedly.

A vulnerability in Weibo's system was exploited to generate the links, but the problem was fixed by 9 pm on June 28, according to an official Sina announcement, and the viral data was removed by 9:25 pm. The passwords and personal information of users were not affected, the announcement said.

Some Weibo users traced the virus back to an account named "hellosamy," which is already non-accessible on Weibo, the Legal Mirror report said.

"The case is under investigation, and we are working on enhanced measures to ensure Weibo safety," an anonymous publicity employee with Weibo told the Global Times on Wednesday.

The cross-site scripting (XSS) hole that made Weibo vulnerable is an ordinary one to which any website is at risk, according to Qihoo 360 Technology Co Ltd, one of China's major Internet companies.

"Although the Weibo virus was just a hacker trick, the implied microblog safety issue should not be neglected," an anonymous 360 publicity representative told the Global Times via e-mail on Wednesday. More Internet safety threats will be spread by microblog, 360's safety center predicts, and traditional anti-virus software is not safe enough, according to the representative.

They have already launched a new "microblog safeguard," the representative said.

Other Chinese microblogs, though not affected by the virus, told the Global Times they will continue to improve safety.

"We have firewalls and certain restrictions to make sure that hackers don't make it in that easily," said a media executive with Sohu's microblogging service surnamed Liu.

"Bugs are normal. What we do is to fix them as soon as we can," he told the Global Times.

Still, China's microblog operators lack adequate safety awareness and need to improve their ability to deal with virus attacks, according to Wei Wuhui, a teacher with Shanghai Jiaotong University and an Internet and new media expert.

"Sina did okay," he said, "but I myself still got some private spam messages until 11 pm or midnight that day, which means there is still some residual spam data."

The "I don't care about privacy invasion" thinking of Chinese Web users has resulted in lax safety protection, Wei said.

He advised that microbloggers not click random links, not post private photos online and to remove all private messages once read.

Print E-mail Bookmark and Share

Go to Forum >>0 Comment(s)

No comments.

Add your comments...

  • User Name Required
  • Your Comment
  • Racist, abusive and off-topic comments may be removed by the moderator.
Send your storiesGet more from China.org.cnMobileRSSNewsletter
主站蜘蛛池模板: 在线观看黄的网站| 日本一卡2卡3卡无卡免费| 伊人久久大香线蕉AV成人| 色婷婷亚洲十月十月色天| 国产成人精品午夜二三区| 91欧美精品综合在线观看| 天天看天天射天天碰| 七仙女欲春3一级裸片在线播放 | 最近中文字幕在线中文视频| 亚洲欧美成人影院| 特级毛片a级毛片在线播放www| 动漫做羞羞的视频免费观看| 老师的兔子好多软水在线看| 国产区精品在线| 99自拍视频在线观看| 国产真实乱人偷精品| 在线精品91青草国产在线观看| 国产黄三级高清在线观看播放| a国产乱理伦片在线观看夜| 妈妈的柔润小说在线阅读| 中国帅男同chinese69| 日本一在线中文字幕天堂| 久久国产成人精品国产成人亚洲 | 啊~嗯~轻点~啊~用力村妇| 西西人体44rt大胆高清日韩 | 四虎精品成人免费永久| 西西人体午夜视频| 国产凌凌漆国语| 黄瓜视频免费看| 国产孕妇孕交视频| 97日日碰人人模人人澡| 国产极品美女高潮无套在线观看| 两个人看的视频播放www| 国产精品免费大片| 2021久久精品国产99国产精品| 国产麻豆精品久久一二三| 99re6免费视频| 国语做受对白xxxxx在线| 99久久综合给久久精品| 在线播放国产一区二区三区| 99久久久久久久|