The big news yesterday was an epic XSS flaw on Twitter that sent the micro-blogging service into chaos. They actually made an announcement during the hack that users should stay off the web-site and use 3rd party services through the API (Software such as Tweetdeck, Seesmic, Gravity etc).
They posted an update on the status blog pretty fast that the XSS had been identified and they were in the midst of patching it.
Hackers have exploited a flaw in Twitter, which results in pop-ups and third-party websites being opened despite users simply hovering over links with their mouse.
Graham Cluely from security firm Sophos said in a blog that at present the flaw is being exploited for “fun and games” although “there is obviously the potential for cybercriminals to redirect users to third-party websites containing malicious code, or for spam advertising pop-ups to be displayed”.
Cluley advised Twitter users to avoid using the Twitter website and instead rely on a third-party client such as Tweetdeck to access the service.
Most ‘attacks’ were pretty harmless with users just having fun with the bug, there were some pretty dodgy incidents though involving shocks sites (goatse or tubgirl anyone?) and hardcore porn sites.
There’s also a good write-up on the Sophos blog here with screen-shots:
A full post on the issue from Twitter is available here:
I like how they are responsible about such things and don’t try to hide them. If you are on Twitter and you want the latest updates about such matters you should follow the @safety account.
Source: Network World
- Sony Pictures Hacked – Employee Details & Movies Leaked
- Gruyere – Learn Web Application Exploits & Defenses
- Critical XSS Flaw Affects WordPress 3.9.2 And Earlier
- Chaos Communication Camp (CCC) 2007 – Germany
- tinfoleak – Get Detailed Info About Any Twitter User
- Phishing Attacks Hits Twitter Users – Utilising Direct Messages
Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 228,447 views
- AJAX: Is your application secure enough? - 119,240 views
- eEye Launches 0-Day Exploit Tracker - 85,109 views