top | item 1334747

Twitter bug: Make anyone follow you on Twitter

155 points| yigit | 16 years ago |blog.gcg.me | reply

131 comments

order
[+] savrajsingh|16 years ago|reply
I would guess this exploit has always been possible until today? What's interesting is that someone has probably been wielding this secret power well before it got outed here on hacker news.
[+] rmorrison|16 years ago|reply
Or, is there anybody whose career took off due to this bug? For example, a musician who got signed primarily because all of the top 50 music producers were following him on twitter.
[+] petercooper|16 years ago|reply
That's true for a lot of shortcuts, hacks, and tricks. People will only tend to reveal tricks if they have no economic value to them (or if using them is so illegal that they'd prefer the fame and respect than the jail time ;-))
[+] ilike|16 years ago|reply
[+] cake|16 years ago|reply
Less than an hour to fix it, without any major data loss or collateral damages that I can see. That's pretty good !
[+] axod|16 years ago|reply
Doesn't seem like a bug to me, it looks like a poor design choice. How many other "special" tweet commands are there?

edit: anyone downmodding care to suggest how putting "accept[username]" in a tweet would be considered a 'bug'?

[+] galactus|16 years ago|reply
amazing. They found out, it seems: right now everyone seems to have 0 following and 0 followers.
[+] icey|16 years ago|reply
I'm really looking forward to seeing how they handle this.
[+] HowardRoark|16 years ago|reply
Thank god. Its everyone.
[+] obsaysditto|16 years ago|reply
Its coincidental that Conan tweeted this message a couple days ago:

"If it ever says I’m following more than one person, I’ve been hacked. I’m a completely monogamous Twitterer—I only follow Sarah Killen."

http://twitter.com/ConanOBrien/status/13631062967

[+] zach|16 years ago|reply
Wow, Conan's Twitter account is not only a test, he's got a user story (that just turned red):

In order to provoke curiosity and amusement

As a celebrity comedy writer and television host

I want to only be shown as following one otherwise-unknown person in Michigan

[+] symesc|16 years ago|reply
In the past couple minutes I watched Conan's page while his "following" list went from about 11 to 2 and then back to just Sarah.

Page refreshes were very slow. The elves are busy.

[+] lpgauth|16 years ago|reply
If you tweet “accept [Twitter Username]”, the other user will automaticly follow you.

eg. "accept snoopdog"

[+] maxklein|16 years ago|reply
Wow, this works. SnoopDogg is now following me: http://twitter.com/snoopdogg. I'm the cartoon figure.
[+] notauser|16 years ago|reply
Bad plan to try this out with an account you value - if they can identify who has used the exploit they will probably ban you when the dust settles.
[+] bena|16 years ago|reply
I don't think they've actually wiped out your followers and people you follow. I think they just prevented us from accessing those tables because I'm still getting tweets from people I follow, I just can't see the lists.
[+] tibbon|16 years ago|reply
Wondering if there will be repercussions for people using this, or if they are able to track it? They aren't able to keep a lot of logs due to the volume.
[+] 146|16 years ago|reply
> They aren't able to keep a lot of logs due to the volume.

That's pretty much untrue.

Anyway, I don't imagine it's too hard to grep the logs for the last day's worth of POST and 'accept .*' and undo all the follows constructed from that.

[+] sjwalter|16 years ago|reply
They are at least able to tell if you've used it--my account just lost all its followers. http://twitter.com/sjwalter

I'd had a legitimate 30ish followers, used this bug a few times, now 0.

[+] noodle|16 years ago|reply
well, i can tell you right now that my followed and following lists were both just now wiped out, and using the accept bug now produces an internal server error.

edit: seems everyone is at 0/0, but the bug still produces an error for me.

[+] fijter|16 years ago|reply
Twitter damage control: TRUNCATE followers;
[+] rmorrison|16 years ago|reply
I can't believe they didn't create an OOB mechanism for accept/deny requests, especially since they send so much meta data w/ each tweet anyway.

This seems like an extremely basic design flaw.

[+] sjwalter|16 years ago|reply
Heh, I used this a bunch of times. It did work just fine, I had all sorts of people following me who really shouldn't care about me. And now I have 0 followers.
[+] yigit|16 years ago|reply
the user who found this says he was trying to tweet "accept pwnz" where accept is a music group name.
[+] julio_the_squid|16 years ago|reply
Yeah! BALLS TO THE WALL!

This is such an odd bug. I guess it goes to show that nobody knows what strange code which should have been removed four years ago lurks in the heart of Twitter.

[+] ErrantX|16 years ago|reply
That's an utterly insane bug! Some kind of debug accidentally left in? Or an admin phrase not authorised properly?
[+] jacquesm|16 years ago|reply
Laziness and security by obscurity.
[+] jasonlbaptiste|16 years ago|reply
better question: does it produce a full follow ie- if i did this bug, would billgates actually see me in his stream? OR does it just increase the follower count+i show up on his sidebar. if its the former, then wow. I know they're clearing it out now, but somebody must have been using this for a while.
[+] mortenjorck|16 years ago|reply
I tried it between my main account and a disused one and tweets from the attacking account showed up both through the web interface and through the API.
[+] tszming|16 years ago|reply
Update (6:30 PM PST): We’ve finished our cleanup of the spurious followings generated a result of this bug. If you are still seeing folks you are following who you didn’t choose to follow, please use the block or unfollow tools to remedy.

Obviously, their so called "cleanup" is incomplete, at least for me :)

[+] jgrahamc|16 years ago|reply
Yes, this does work. Now what's the opposite verb to make someone unfollow me?