Security News > 2021 > July > Pro-Trump ‘Gettr’ Social Platform Hacked On Day One

Pro-Trump ‘Gettr’ Social Platform Hacked On Day One
2021-07-07 03:27

Gettr, a social media platform set up by allies of former President Donald Trump, was still wet and squirming when it got hacked - twice.

Gettr - a Twitter-esque platform with posts and trending topics - was quietly launched on Thursday by Jason Miller, a senior adviser to Trump who's been teasing it for months.

First spotted by Politico, Gettr advertises itself on the Google Play and Apple app stores as a platform "Founded on the principles of free speech, independent thought and rejecting political censorship and 'cancel culture'" and as "a non-bias social network for people all over the world."

"Threat actors were able to take advantage of bad API implemented on Trump's recent social media platform, Gettr. This allowed them to extract usernames, names, bios, bdays, but most importantly, the emails which were supposed to be private, of over 85,000 users," Gal tweeted, including images of the hacked data.

Threat actors were able to take advantage of bad API implemented on Trump's recent social media platform, Gettr.

On the day Gettr launched, security and privacy researchers flagged Gettr's poorly programmed, bug-ridden API. One of them as Ashkan Soltani, a security and privacy researcher and former FTC chief technologist who found one bug that would allow anyone to brute-force the app's API by feeding it a list of email addresses and getting a response that shows which ones have successfully registered with Gettr, the other which allowed for the viewing of a list of users that any given user has muted or blocked.


News URL

https://threatpost.com/trump-gettr-social-media-hacked-day-1/167574/