Hacker attack shuts down Twitter, Facebook also slows down (Update 2)

August 6, 2009 Hackers attack Twitter, Facebook also slows down (AP)

Enlarge

Twitter user and California State Senate candidate Edward Paul Reyes, left, works with a colleague on his twitter page at a local Starbucks in Los Angeles on Thursday, Aug. 6, 2009. A hacker attack Thursday shut down the fast-growing messaging service Twitter for hours, while Facebook experienced intermittent access problems. (AP Photo/Damian Dovarganes)

(AP) -- Hackers on Thursday shut down the fast-growing messaging service Twitter for hours, while Facebook experienced intermittent access problems.

Twitter said it suffered a denial-of-service attack, in which hackers command scores of computers toward a single site at the same time, preventing legitimate traffic from getting through.

The attacks may have been related to the ongoing political conflict between Russia and Georgia. They started with hackers using a botnet to send a flurry of spam e-mail messages that contained links to pages on Twitter, Facebook and other sites written by a single pro-Abkhazia activist, according to Bill Woodcock, research director of the San Francisco-based Packet Clearing House, a nonprofit that tracks Internet traffic.

Russia recognized as independent the breakaway regions of South Ossetia and Abkhazia after a brief war with Georgia a year ago.

When people clicked on the links, they were taken to the activist's legitimate Web pages, but the process of loading the pages at such volumes overwhelmed some servers and disrupted service, Woodcock said. He said it's hard to immediately tell whether it was a case of hackers trying to punish the sites for publishing views they disagree with, or if they were directing traffic to the sites out of sympathy for the activist's message.

"There's very little way of distinguishing which side was taking this action, because either side could hypothetically benefit from it," Woodcock said.

The fact that a relatively common attack could disable such a well-known Web site shows just how young and vulnerable Twitter still is, even as it quickly becomes a household name used by celebrities, large corporations, small businesses and even protesters in Iran.

"Clearly they need a stronger infrastructure to be able to fight this kind of attack," said Graham Cluley, senior technology consultant at computer security firm Sophos. Twitter's tech support teams, he added, "must be frankly out of breath" trying to keep up with the site's enormous growth.

According to comScore, Twitter had 20.1 million unique visitors in the United States in June, some 34 times the 593,000 a year earlier.

For Twitter users, the outage meant no tweeting about lunch plans, the weather or the fact that Twitter is down.

"I had to Google search Twitter to find out what was going on, when normally my Twitter feed gives me all the breaking news I need," said Alison Koski, a New York public-relations manager. She added she felt "completely lost" without Twitter.

The Twitter outage began at about 9 a.m. EDT and lasted a few hours.

Facebook, whose users encountered intermittent problems Thursday morning, was also the subject of a denial-of-service attack, though it was not known whether the same hackers were involved. Unlike Twitter, Facebook never became completely inaccessible. Facebook said no user information was at risk.

LiveJournal, a 10-year-old online diary and blogging site that has waned in popularity in recent years, was also the subject of a denial-of-service attack that lasted about an hour Thursday morning, the company said.

By early afternoon both Twitter and Facebook seemed to be functioning, giving cubicle-bound social media addicts a collective sigh of relief. Twitter warned, though, that as it recovers, "users will experience some longer load times and slowness."

Technology business analyst Shelly Palmer told AP Radio that denial-of-service attacks are a reality of the information age.

"People tend to want to take sites that are very public and go after them," said Palmer, managing director of Advanced Media Ventures Group. "In fact you'd be surprised how many sites for major companies are really attacked on a daily basis. This is a crime, it's a real crime and it should be treated that way."

Earlier this week, Gawker Media, which owns the eponymous media commentary blog and other sites, was also attacked. In a blog post, Gawker said Tuesday it was attacked by "dastardly hackers," leading to server problems that caused network-wide outages Sunday and Monday. It was not immediately clear whether those attacks were related to Twitter's.

Thursday's was not the first - and likely not the last - outage for Twitter.

Besides planned maintenance outages, overcapacity can cripple Web sites, especially such fast-growing ones as Twitter and Facebook.

In fact, service outages on Twitter once were so common that management began posting a "Fail Whale" logo on the Web site to signal when the service was down. The logo featured a whale being hoisted above the water by a flock of birds.

Millions of Twitter users aren't familiar with the 3-year-old service's history of frequent outages because they began tweeting in the past six months, around the same time that the San Francisco-based company had was spending more money to increase its computing power and reduce the disruptions. With the added capacity, the Fail Whale rarely surfaces any more.

Even so, the entire site being down means Twitter hasn't put enough measures in place to prevent such an attack, Cluley said. That could include working with Internet service providers to filter potentially malicious requests from legitimate ones, as well as having servers spread out around the world.

Denial-of-service attacks are typically carried out by "botnets" - armies of infected computers formed by spreading a computer virus that orders compromised machines to phone home for further instructions. They are generally used to send out spam or steal passwords, though some can be commanded to overwhelm Web sites.

Successful attacks on popular Web sites were common earlier this decade. Sites such as eBay, Amazon.com and CNN were overwhelmed by such attacks, sometimes for days, in 2000.

But Thursday's attack underscores the fact that no one is immune.

"With these attacks, if you get enough infected machines ... you can take down anyone," said Dmitri Alperovitch, vice president of threat research at security vendor McAfee Inc.

Last month, dozens of U.S. and South Korean sites, including those of the White House and South Korea's presidential Blue House, were targeted in denial-of-service attacks.

For Lev Ekster, who runs a mobile cupcake truck called CupCakeStop in New York, Thursday's Twitter hiccup meant no tweets to customers and fans on the truck's location and the day's flavors.

But it wasn't the end of the world.

"As soon as I saw the Twitter outage, I went on to our fan page," said Ekster, who also uses Twitter to get reviews of his cupcakes, find employees and let people know about giveaways.

The lesson, he says, is "not to limit yourself to Twitter and live or die by ."

---

AP Technology Writer Jordan Robertson contributed to this story from San Francisco.
©2009 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.8 /5 (6 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • docknowledge - Aug 06, 2009
    • Rank: 5 / 5 (3)
    Steal billions annually from electronic transactions? *Yawn*. What??? They're attacking Twitter?? Omg, this is outrageous!
  • bmcghie - Aug 07, 2009
    • Rank: 2 / 5 (1)
    Alison Koski is a twit.
  • RayCherry - Aug 07, 2009
    • Rank: 5 / 5 (2)
    Actually, there is insufficient evidence to say this was an intended hack, or over enthusiastic viral marketing ...

    Seems both sites need better bandwidth (or cache) on demand, or (unpopular) click inhibiters which disable links when they are in high demand.
  • Velanarris - Aug 07, 2009
    • Rank: not rated yet
    I prefer anti-social networking. That's when you just unplug and go sit on the couch. Why you may ask? Well, because... fuck it.
  • kirkamr - Aug 07, 2009
    • Rank: not rated yet
    really, who cares

August 6, 2009 all stories

Comments: 5

4.8 /5 (6 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Is quitting Twitter more popular than re-tweeting?
    created Apr 30, 2009 | popularity not rated yet | comments 0
  • AT&T says Web site block was not censorship
    created Jul 27, 2009 | popularity not rated yet | comments 0
  • Social networking aggregator sues Facebook
    created Jul 10, 2009 | popularity not rated yet | comments 0
  • Spears, DeGeneres Twitpic accounts hacked
    created Jun 29, 2009 | popularity not rated yet | comments 0
  • Twitter all-star? Best Buy puts number at 250
    created Jul 21, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • Shortening Boat Trailer
    created Nov 18, 2009
  • Strain Gage Test Advice
    created Nov 17, 2009
  • How Could I do This? Motor to open and close doors on a timer??
    created Nov 17, 2009
  • More from Physics Forums - General Engineering

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 2 hours ago | popularity not rated yet | comments 0

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Ubisoft steps up videogame fitness with virtual coach

Technology / Software

created 2 hours ago | popularity not rated yet | comments 0

French videogame powerhouse Ubisoft will have a virtual fitness coach whipping Wii users into shape starting Tuesday.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created 13 hours ago | popularity 4.4 / 5 (19) | comments 13

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...


UK police make 2 Trojan computer virus arrests

Technology / Internet

created Nov 18, 2009 | popularity 5 / 5 (1) | comments 10

(AP) -- A couple suspected of helping spread some of the Internet's most aggressive computer viruses has been arrested in the English city of Manchester, police said Wednesday.