Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Beware Of Twitter: Security Flaw Spreading

Featured Replies

Beware of Twitter: Security Flaw Spreading

Security firm Sophos posted a blog entry early Tuesday highlighting a new and potentially dangerous hack of Twitter's Web interface that's begun to make the rounds. It affects only Twitter.com, not third-party clients.

Here's how it works, basically: By putting a bit of JavaScript code ("onmouseover") into a URL in a tweet, a user can cause a pop-up message to emerge when someone hovers a cursor over that link. Sophos notes that right now primary exploiters of the loophole are using it for "fun and games," but that it could potentially be used by spammers or purveyors of malicious code. It appears to work in both the redesigned Twitter Web interface that was launched last week as well as its predecessor.

"Mouseover" hacks are not particularly complicated, and have been implemented in vulnerable e-mail clients for years.

Sophos noted that many Twitter users are playing around with it but that the company hasn't put out an official reaction. Representatives from Twitter were not immediately available for comment.

UPDATE (8:38 a.m. ET): Sophos notes that the exploit is spreading rapidly and that it's now being used to redirect to some hardcore porn sites.

UPDATE (8:51 a.m. ET): The security hole is now being used to "auto-tweet" more mouseover links, and thousands of Twitter users are falling prey to it. For the time being, using a third-party Twitter client may be the safest option.

SS attack identified and patched. 26 seconds ago

UPDATE (9:51 a.m. ET): Twitter says it has identified and is patching the exploit. "We expect the patch to be fully rolled out shortly and will update again when it is," Twitter said on its blog.

-- CBS News 2010-09-21

This has been fixed by Twitter. Not an issue anymore.

  • Author

UPDATE (10:04 a.m. ET): Twitter says the exploit has been fully patched.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.