WebNewser - Social Media for Media Pros


Twitter Security Hole Still Exists

Twitter Operations' John Adams claimed that the social-networking site patched a bug that allowed U.K.-based search-engine-optimization expert Dave Naylor to insert JavaScript code into tweets where application developers would normally link to product Websites, but TechCrunch and Naylor both say: Not so fast.

Naylor apparently duplicated his feat from Tuesday, creating a dummy Twitter account and inserting code that prompts a dialog box to pop up when accessed through the Twitter Website. TechCrunch reports that Twitter never got in touch with Naylor after he reported the issue, instead attempting to repair it on its own.

Naylor wrote on his blog:

With a few minutes' work, someone with a bit of technical expertise could make a Twitter "application" and start sending tweets with it. Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets and they are logged in to Twitter, their account could be taken over.
Imagine that for a moment. Simply by seeing one of these tweets, code can be run inside your browser impersonating you and doing anything that your browser can do. Perhaps it may simply redirect you to a pornographic Website? Or maybe delete all of your tweets? Send a message to all of your friends? Maybe it would delete all of your followers, or worse still, just send the details needed to log in to your account off to another Website for someone to use at their leisure.

new on mediabistro.com

How to Write an Arts and Culture Review

Learn everything you need to know to write a smart, publishable review of music, film, books, theater or any other arts and culture topic.
Watch the video

Email This Post

Fill out the following information and click on the Send button in order to send this post, Twitter Security Hole Still Exists, to a friend.
Friend's name
Friend's email address
Your name
Your email address
Note to your friend (optional, max 200 Characters)

Read more on WebNewser >

Social Media for Media Pros
WebNewser in Your Inbox
Mobile Version
RSS Feed
Our Blog Network

BayNewser

WebNewser

PRNewser

TVNewser

MobileContentToday

MediaJobsDaily

FishbowlNY

FishbowlDC

FishbowlLA

AgencySpy

GalleyCat

UnBeige

WebNewser Editors

Managing Editor:

Chris Nerney

Editor:

David Cohen

About WebNewser

Follow WebNewser

Email WebNewser

Anonymous Tips

  WebNewser twitter feed loading...

View twitter directly

Follow WebNewser via Twitter
Archives

November 2009

October 2009

September 2009

August 2009

more...

Topics

ABC.com

About

About Us - Modules

About Us - Subheader Module

Awarding Web

Biz Web

Blog-nalism

CBS Interactive

CES 2009

CNBC.com

CNN.com

Connected

E-Publishing

FoxNews.com

Global Web

Google

Hacked

Magazines

MobileWeb

msnbc.com

NAB-RTNDA '09

NBC.com

News Alert

Newspapers

Personalities

Political Web

Radio Waves

Rush Hour

Social Nets

SXSW 2009

The New, New Thing

Twitter

User Generated

Video Sites

Web Ratings

Web Ticker

Web TV

Web's Revolving Door

WebNewser Announcements

Yahoo!

Links

AllThingsD

Beet.TV

Broadcasting & Cable

BuzzMachine

Lost Remote

The Medium

Shelly Palmer

PaidContent

Romenesko

Pogue's Posts

Quantcast

TechCrunch

TV.com

TV Decoder

TVNewsday

TVWeek

The Wrap

mb News Feed

Job Listings

Featured Listings

Managing Director
Pro-Media Communications
New York, NY

Art Director
5280 Magazine
Denver, CO

Reporting and Data Analyst
Varick Media Management
New York, NY


mediabistro.com l Member Benefits l Jobs l Freelance Marketplace l Courses l Events l Forums l Content
mediabistro Blogs: Media News l TVNewser l GalleyCat l UnBeige l FishbowlNY l FishbowlLA l FishbowlDC l PRNewser l AgencySpy
MobileContentToday l WebNewser l BayNewser l MediaJobsDaily l mbToolbox
Site Map l Advertising/Sponsorships l Partners l About Us l Contact Us/Help

internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers