TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Twitter bug: Make anyone follow you on Twitter

155 点作者 yigit大约 15 年前

44 条评论

savrajsingh大约 15 年前
I would guess this exploit has always been possible until today? What's interesting is that someone has probably been wielding this secret power well before it got outed here on hacker news.
评论 #1335156 未加载
评论 #1335349 未加载
ilike大约 15 年前
Official:<p><a href="http://status.twitter.com/post/587210796/follow-bug-discovered-remedied" rel="nofollow">http://status.twitter.com/post/587210796/follow-bug-discover...</a>
评论 #1335638 未加载
评论 #1335921 未加载
galactus大约 15 年前
amazing. They found out, it seems: right now everyone seems to have 0 following and 0 followers.
评论 #1335135 未加载
评论 #1335093 未加载
obsaysditto大约 15 年前
Its coincidental that Conan tweeted this message a couple days ago:<p><i>"If it ever says I’m following more than one person, I’ve been hacked. I’m a completely monogamous Twitterer—I only follow Sarah Killen."</i><p><a href="http://twitter.com/ConanOBrien/status/13631062967" rel="nofollow">http://twitter.com/ConanOBrien/status/13631062967</a>
评论 #1335213 未加载
评论 #1335560 未加载
评论 #1335215 未加载
lpgauth大约 15 年前
If you tweet “accept [Twitter Username]”, the other user will automaticly follow you.<p>eg. "accept snoopdog"
maxklein大约 15 年前
Wow, this works. SnoopDogg is now following me: <a href="http://twitter.com/snoopdogg" rel="nofollow">http://twitter.com/snoopdogg</a>. I'm the cartoon figure.
评论 #1334967 未加载
bena大约 15 年前
I don't think they've actually wiped out your followers and people you follow. I think they just prevented us from accessing those tables because I'm still getting tweets from people I follow, I just can't see the lists.
tibbon大约 15 年前
Wondering if there will be repercussions for people using this, or if they are able to track it? They aren't able to keep a lot of logs due to the volume.
评论 #1337194 未加载
评论 #1337257 未加载
评论 #1335049 未加载
评论 #1335064 未加载
评论 #1335162 未加载
fijter大约 15 年前
Twitter damage control: TRUNCATE followers;
rmorrison大约 15 年前
I can't believe they didn't create an OOB mechanism for accept/deny requests, especially since they send so much meta data w/ each tweet anyway.<p>This seems like an extremely basic design flaw.
sjwalter大约 15 年前
Heh, I used this a bunch of times. It did work just fine, I had all sorts of people following me who really shouldn't care about me. And now I have 0 followers.
评论 #1335084 未加载
chegra大约 15 年前
Sweet works for me. Check my followers: <a href="http://twitter.com/chegra" rel="nofollow">http://twitter.com/chegra</a>
评论 #1335033 未加载
yigit大约 15 年前
the user who found this says he was trying to tweet "accept pwnz" where accept is a music group name.
评论 #1335594 未加载
gokhan大约 15 年前
The Turkish user who found the bug explains it here (in Turkish): <a href="http://inci.sozlukspot.com/e/4266098/" rel="nofollow">http://inci.sozlukspot.com/e/4266098/</a><p>And people wondering why Axl Rose is following him here :) <a href="http://www.mygnrforum.com/index.php?showtopic=164026&#38;st=0" rel="nofollow">http://www.mygnrforum.com/index.php?showtopic=164026&#38;st=...</a>
ErrantX大约 15 年前
That's an utterly insane bug! Some kind of debug accidentally left in? Or an admin phrase not authorised properly?
评论 #1335593 未加载
jasonlbaptiste大约 15 年前
better question: does it produce a full follow ie- if i did this bug, would billgates actually see me in his stream? OR does it just increase the follower count+i show up on his sidebar. if its the former, then wow. I know they're clearing it out now, but somebody must have been using this for a while.
评论 #1335304 未加载
评论 #1335148 未加载
tszming大约 15 年前
Update (6:30 PM PST): We’ve finished our cleanup of the spurious followings generated a result of this bug. If you are still seeing folks you are following who you didn’t choose to follow, please use the block or unfollow tools to remedy.<p>Obviously, their so called "cleanup" is incomplete, at least for me :)
InclinedPlane大约 15 年前
Allegedly fixed, twitter is working on rolling back abuses of the hack.<p><a href="http://status.twitter.com/post/587210796/follow-bug-discovered-remedied" rel="nofollow">http://status.twitter.com/post/587210796/follow-bug-discover...</a>
评论 #1335373 未加载
jgrahamc大约 15 年前
Yes, this does work. Now what's the opposite verb to make someone unfollow me?
评论 #1335096 未加载
djb_hackernews大约 15 年前
watch everyone play!<p><a href="http://search.twitter.com/search?q=accept" rel="nofollow">http://search.twitter.com/search?q=accept</a>
jeiting大约 15 年前
Wow, tested and verified.<p>Somebody is working late tonight.
maxklein大约 15 年前
I wonder if they are going to be able to undo this. Do they have a two sided log of the follow process? If it's just one-sided, they may be able to fix the bug but not to reverse the damage.
评论 #1335333 未加载
TrevorBramble大约 15 年前
Interesting. My "following" and "followers" counts just dropped to 0.
评论 #1335087 未加载
thedjpetersen大约 15 年前
Jason Calacanis dream come true :P
olh大约 15 年前
Seems that the fix is just a filter. Is anyone else trying to bypass with html ascii? A few minutes ago, a prompt with the html ascii returned a +0x36 on every char. Now it does not give feedback.<p>"accept BillGates": &#38;#61 ;&#38;#63 ;&#38;#63 ;&#38;#65 ;&#38;#70 ;&#38;#74 ;&#38;#20 ;&#38;#42 ;&#38;#69 ;&#38;#6C ;&#38;#6C ;&#38;#47 ;&#38;#61 ;&#38;#74 ;&#38;#65 ;&#38;#73 ;<p>Maybe they already <i>really</i> fixed this bug (I hope).
nutmeg大约 15 年前
There could be notoriety for anyone who does this to Conan O'brien. He only follows one person AFAIK.<p>Edit: Looks like this probably already happened.
评论 #1335019 未加载
评论 #1335004 未加载
aditya大约 15 年前
Whatever it was, got removed or keeled over...
评论 #1334951 未加载
whakojacko大约 15 年前
Even without this bug, I dont think they should still allow commands via tweet at all. It made sense when most tweets were via SMS, but not anymore...Maybe for emerging markets with heavy SMS usage, add a 2nd number to send commands to isolate the two?
评论 #1335597 未加载
mrduncan大约 15 年前
They appear to be working on some sort of fix right now.<p>If you look at "following" lists, everything is showing up as zero for me right now, as in it shows that I'm not following anyone. All other users that I check are also showing that they aren't following anyone.
blizkreeg大约 15 年前
Oooo approaching 2012 ;) Louisiana oil spill. Massive Twitter bug. Sticky finger Dow collapse. Facebook losing it's privacy mojo.<p>And to top it off, one line of code I checked in late last night prevented 200 new users from signing up on my freshly minted site.
mtinkerhess大约 15 年前
It appears that they just wiped everyone's list of followers? My feed still works though.
orblivion大约 15 年前
This is up there with putting everybody in a root terminal by default on their Androids.
lukeqsee大约 15 年前
Everyone shows 0 followers, but your stream still shows those you follow. Interesting.
RyanMcGreal大约 15 年前
BBC has a report on this:<p><a href="http://news.bbc.co.uk/2/hi/technology/10106166.stm" rel="nofollow">http://news.bbc.co.uk/2/hi/technology/10106166.stm</a>
araneae大约 15 年前
Exploit is fixed, and follower lists are rolled back, but they didn't do a perfect job...<p>Felicia Day is still following me. ^-^
shrikant大约 15 年前
Link doesn't work - does a server hammering lead to a 404? I didn't know it could...
goldham大约 15 年前
I would not want to be in the Twitter offices today. Good day to call in sick.
dmn001大约 15 年前
Is it broken now? Both followers and follow count is 0 now?!
jeiting大约 15 年前
Now I am getting a 502 when I try to post accept messages.
maxklein大约 15 年前
Okay, all followers of everyone just dropped to 0...
评论 #1335043 未加载
yigit大约 15 年前
here is the official twitter status blog: <a href="http://status.twitter.com/" rel="nofollow">http://status.twitter.com/</a>
CoryMathews大约 15 年前
Wow they fixed that really fast.
lukejduncan大约 15 年前
mirror?
评论 #1334914 未加载
acangiano大约 15 年前
EDIT: My original message invited people not to try this. It turns out that everyone's counter is showing zero followers, regardless of whether you tried the hack or not. Thanks Travis for pointing this out. I was misled by my desktop client which cached my follower number.
评论 #1335116 未加载
评论 #1335375 未加载