Tumblr worm hitting websites, posting identical message from GNAA

Filed Under: Malware, Social networks, Spam, Vulnerability

There appears to be a worm impacting many Tumblr websites, defacing pages with an identical message.

Hacked Tumblr webpage

The message, was posted alongside an image of a man and the logo of a group called the "GNAA".

The "GNAA", the Gay N***** Association of America, is an association of internet trolls that seems to have a particular delight in winding up bloggers with racist posts.

At the time of writing, Tumblr does not appear to have said anything about the problem. However, many Tumblr users have turned to other social media outlets to share their concerns that they have been hit by a worm.

For instance, news website The Verge told its readers that its Tumblr had fallen victim to the hack:

The hack is still being investigated, and we'll update this article as we find out more. In the meantime, however, we would recommend that internet users do not visit Tumblr sites - in particular if they run their own Tumblr page and are logged into the site as this is a possible method through which the attack could be spread.

Of course, Tumblr isn't the first social media site to be hit by a fast-spreading worm. For instance, a couple of years ago Twitter was widely hit by a worm that exploited cross-site-scripting (XSS) vulnerability.

See also: How the Tumblr worm spread so quickly

Update: Tumblr has now issued a statement about the security problem:

When I tried to post to Tumblr from a test account I was presented with the following message, which may indicate that Tumblr has temporarily disabled posting to prevent the worm from spreading further:

Tumblr stops new posts

Further update: Tumblr says that it has now resolved the issue:

, , , ,

3 Responses to Tumblr worm hitting websites, posting identical message from GNAA

  1. KLD says:

    Weird...Tumblr has been up all night (and all day) for me.
    They're infamous for downtime, though, so I wouldn't be surprised if that's just a glitch in the system.

  2. Last Laugh says:

    The perpetrators of the virus must be laughing. Not only did it post itself to any number of Tumblr accounts, it's now magically spread to countless other blogs, including this one, where it's repeated in full. Twice.

  3. justkeepit says:

    maybe though, but then i haven't seen my dashboard almost 3 weeks haha

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>

About the author

Graham Cluley has worked in the computer security industry for more than 20 years, developing anti-virus software and doing quite a lot of talking about internet threats. He's won awards for his blogging, but is proudest of the text adventure games he wrote when he was still wearing short trousers. You can learn more about those (the games, not the trousers) at grahamcluley.com. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.