Twitter hacked via security flaw

Local, national, international and oddball news stories

Twitter hacked via security flaw

Postby dutchman » Tue Sep 21, 2010 3:56 pm

The main Twitter website has been hacked via a security flaw.

Image

Users who move their cursor over blacked-out text have been automatically Tweeting or Retweeting the same message. Some accounts have automatically posted a message in oversize text, making their page and those of their followers unreadable.

In a blog post, Graham Cluely of security firm Sophos reported that the flaw allows messages and pop-up windows from third parties to open in users' browsers. These pages potentially contain spam or malicious code.

Cluely said: "The Twitter website is being widely exploited by users who have stumbled across a flaw which allows messages to pop up and third-party websites to open in your browser just by moving your mouse over a link.

"Hopefully Twitter will shut down this loophole as soon as possible - disallowing users to post the onMouseOver JavaScript code, and protecting users whose browsing may be at risk."

He added: "Right now you might be safer using a third-party Twitter client rather than the Twitter.com website."

Cluely noted that the Twitter page belonging to Sarah Brown, the wife of former prime minister Gordon Brown, has attempted to direct her one million followers to a "hardcore porn site based in Japan".

At present Twitter client TweetDeck seems unaffected by the hack.
User avatar
dutchman
Site Admin
 
Posts: 55299
Joined: Fri Oct 23, 2009 1:24 am
Location: Spon End

Return to News

Who is online

Users browsing this forum: No registered users and 5 guests

  • Ads