Peaches Posted March 22, 2009 Report Share Posted March 22, 2009 21 March 2009, 11:53 Twitter XSS vulnerability Secure Science Corporation has published a proof of concept XSS vulnerability which it says could be spread virally, similar to a worm, on the popular microblogging service, Twitter. The exploit is similar to the "Don't click" clickjacking exploit found at the end of February. When the users inadvertently clicked the links while logged into their accounts, the embedded script automatically re-posted itself under their Twitter account. The exploit makes use of a web programming error on Twitter's support site, to post the unwanted message. The test code provided by Secure Science posts the message "@XSSExploits I just got owned!" to the victim's profile. According to Lance James, chief scientist at Secure Science, the attack could be modified so that there is no warning screen and include a message that would make users more likely to click on it. http://www.h-online.com/security/Twitter-X...y--/news/112905 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.