Slashdot Mirror


Twitter Hit With Second Worm In a Week

adeelarshad82 writes "Days after a site update unleashed a Twitter cross-site scripting attack, the micro-blogging site was again hit with a bug that spread via questionable links. The offending messages appeared on a user's Twitter feed with 'WTF:' followed by a link. If you clicked on that link, you were taken to a blank page, but behind the scenes, the worm would post vulgar messages on your account that discussed, well, sex involving goats."

5 of 97 comments (clear)

  1. Re:where is that goatsex link when you need it? by ShaunC · · Score: 5, Informative

    WTF: Goatse

    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  2. Re:I guess this script is baaaad for you. by Bill,+Shooter+of+Bul · · Score: 4, Informative

    No. This is a Cross site Request Forgery attack. The Script in this case, was on the linked site, not in the tweet.

    For those not in the know:

    OWASP Cross Site Request Forgery Prevention sheet Sheet

    --
    Well.. maybe. Or Maybe not. But Definitely not sort of.
  3. Re:I guess this script is baaaad for you. by nacturation · · Score: 4, Informative

    This post explains it quite well: http://www.andrewnacin.com/2010/09/26/csrf-twitter/

    Essentially, just create one or more iframes, with the iframe source set to http://twitter.com/share/update?status=WTF+PAYLOAD

    As long as you're logged into Twitter via the web, it will auto-post that update without any request for permission from you.

    --
    Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
  4. Re:Great - more 4Chan? by icebraining · · Score: 4, Informative

    Or you could install this GM script which expands them to the real URL without actually loading it.

  5. Re:where is that goatsex link when you need it? by Jedi+Alec · · Score: 3, Informative

    Next up: Twitter worms that discuss Natalie Portman naked and petrified, GNAA trolls and of course the classic penis bird.

    --

    People replying to my sig annoy me. That's why I change it all the time.