X fixes URL blunder that could enable convincing social media phishing campaigns
- Reference: 1712745434
- News link: https://www.theregister.co.uk/2024/04/10/x_fixes_url_blunder/
- Source link:
Users started noticing on Monday that X's programmers implemented a rule on its iOS app that auto-changed Twitter.com links that appeared in Xeets to X.com links.
Even though the Twitter.com domain is still active, used by many, and important pages such as its Help Center still rely on the domain, apparently it was imperative to the team that Xeet links simply must be on-brand.
[1]
The issue with this new feature was that it was implemented poorly, changing any mention of "Twitter" anywhere in a URL string to "x," which of course opened up a bag of security worms.
[2]
[3]
Users quickly realized the buggy implementation allowed them to freely publicize potentially malicious web pages. Posting a link to netflitwitter[.]com would be automatically changed by the X platform to display Netflix.com – a legitimate domain.
Crucially, however, if a user tapped on that link, which again was displayed to them as Netflix.com , they would instead be taken to the original link netflitwitter[.]com , a domain that was kindly picked up by a fast-acting Xeeter so it couldn't be used by bad actors.
[4]
The potential for abuse here would be rife, given the number of legitimate, well-known brands most people would blindly trust. Netflix, Plex, Roblox, Clorox, Xerox – you get the picture.
That's not even considering the potential for abuse of X-rated sites horned-up users might be otherwise too flustered to double-check for authenticity.
Attackers could feasibly [5]copy legitimate web pages to steal credentials , or skip the trouble and simply use it as a [6]malware -dropping tool, or any number of other possibilities.
[7]
Unsurprisingly, X hasn't addressed this publicly – likely in an attempt to avoid drawing attention to the blunder. We've also given up following journalistic practice when it comes to trying to contact its press team.
For those not in the know, soon after Musk took over, he fired the PR team and set all inbound communications to its inbox to auto-reply with a poop emoji. Now it's just: "Busy now, please check back later."
[8]Thank the bots, your blue check is back on X
[9]Malicious xz backdoor reveals fragility of open source
[10]Apple fans deluged with phony password reset requests
[11]Meta connects Threads to the Fediverse
Without any official account of the timeline here, we resort to searching past Xeets to see how long the error went unchecked. Based on [12]various users' [13]posts , it appears it was allowed to run for at least nine hours, but potentially longer.
According to tests at Reg towers on Wednesday morning, the issue appears to have been reversed. Netflitwitter[.]com now reads as such, but Twitter.com is auto-changed to X.com .
It appears that the Twitter-to-X policy doesn't apply when the domain is written in all-caps, but in every combination we tried we couldn't get the old trick to work. It seems properly fixed.
Nevertheless, it's an embarrassing blunder for the X devs that could have led to some nasty outcomes. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zha3nSDzx9FxbJkKV2DZ4QAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zha3nSDzx9FxbJkKV2DZ4QAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zha3nSDzx9FxbJkKV2DZ4QAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zha3nSDzx9FxbJkKV2DZ4QAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/10/24/dhl_phishing_scams/
[6] https://www.theregister.com/2024/01/24/ncsc/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zha3nSDzx9FxbJkKV2DZ4QAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2024/04/04/x_blue_checks_twitter/
[9] https://www.theregister.com/2024/04/01/xz_backdoor_open_source/
[10] https://www.theregister.com/2024/03/27/apple_passcode_attack/
[11] https://www.theregister.com/2024/03/22/meta_threads_metaverse_connection/
[12] https://twitter.com/t3dotgg/status/1777425000133468582
[13] https://twitter.com/Arcticstar0/status/1777554400787009558
[14] https://whitepapers.theregister.com/
Yes, but the West Wittering Parish Council* would sue, if only they could afford it.
*https://www.westwitteringparishcouncil.gov.uk/
Wow! Slumdog Millionaire moment!
I don't need to click the link, cos I know exactly where they are. I used to use their beach for kite traction sports.
In fact I used to be in the top 4 or 5 kite buggy freestylers in Hampshire ........ but only cos there were only 4 or 5 kite buggy freestylers in Hampshire!
That programmer is presumably now an etwitter-programmer.
If I had a jellybean for every time a popular website had a domain-squatting risk due to an API with a half-ascii'd autoreplace issue creating arbitrary URLs, I would have two jellybeans. Which isn't a lot, but it's weird that it happened twice this week.
https://corporateclash.net/news/article/153
https://sheriffcranky.substack.com/p/datadog-has-a-security-footgun
"Xeets"
Where the "ee" is pronounced as the short "i" vowel sound I assume.
Re: "Xeets"
Zits
I don't use X because I don't like squeezing my zits (*)
(*) into 280 characters
All is good
x.com still redirects to twitter.com nicely.
Re: All is good
good?
It'd be better if it redirected to itself. Let the users get stuck in an endless loop.
Or otherwise just produce an error.
Or a blank page, which would naturally have about the same amount of interesting content as the current redirect produces.
Re: All is good
Better still, Error 732: Fucking Unic💩de .
regex is an art
And apparently some of the xeet coders are artless.
They fell victim to one of the clbuttic blunders
The post is required, and must contain letters.
What a bunch of ...
It starts with an "M", and ends in "orons".
Distressingly the whole thing hasn't collapsed into a pile of X as we were all hoping.
Let's be honest - I've watched enough Netflix originals to know that going to their real URL won't save you from bad actors.
So they've fitwittered it then?