Technology content trusted by users in North America and around the world.
4,965 Articles | 29,991 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

USA EditionYou are located: Home > All News > Hacking & Security News > Stay away from Twitter.com; it's being exploited with simple code

Stay away from Twitter.com; it's being exploited with simple code

By: (more) | Hacking & Security News | Posted: Sep 21, 2010 1:41 pm

If you haven't seen already, Twitter.com is under attack exploiting a flaw in its system with a simple code called "onmouseover" that is used to execute code or a command when your mouse cursor is moved over the bad area.

 

My @camwilmot account has personally been affected just now and as far as I can see, it only affects the front page of Twitter.com and not other pages such as your profile page.

 

 

Basically what I did by mistake was move my mouse over a strange tweet with black color background over the text and then that took over my Chrome v6 browser. Now when I load the old Twitter.com I am unable to access the page and if I click anywhere a link is opened in a new window. Meanwhile tweets are automatically being made consisting of re-tweets of the latest tweets from a Twitter user called "Matsta". Is this some sort of attempt to push Twitter to move all of its users to the new Twitter.com design that was unveiled last week or just a way to highlight flaws in Twitter's security? Some Twitter users are reporting that the new Twitter.com is not affected, but at the time of writing we could not confirm if this is true or not.

 

No doubt Twitter's developers and coders are hard at work right now putting a fix to this. As for now, you should probably avoid Twitter.com and stick to a Twitter client such as TweetDeck which isn't affected by this exploit.

 

06:45 US PST UPDATE: Here is an update from Twitter: We've identified and are patching a XSS attack; as always, please message @safety if you have info regarding such an exploit.

 

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Western Digital Scorpio Blue (WD5000LPVT) 500GB HDD Review
  • Upcoming Content: Scythe Mugen 4 Tower CPU Cooler Review
  • Upcoming Content: NZXT Grid 10 Port Fan Hub Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Hacking & Security News Posts

View More Hacking & Security News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases