Twitter Hit With Second Worm In a Week
adeelarshad82 writes "Days after a site update unleashed a Twitter cross-site scripting attack, the micro-blogging site was again hit with a bug that spread via questionable links. The offending messages appeared on a user's Twitter feed with 'WTF:' followed by a link. If you clicked on that link, you were taken to a blank page, but behind the scenes, the worm would post vulgar messages on your account that discussed, well, sex involving goats."
WTF: Goatse
Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
No. This is a Cross site Request Forgery attack. The Script in this case, was on the linked site, not in the tweet.
For those not in the know:
OWASP Cross Site Request Forgery Prevention sheet Sheet
Well.. maybe. Or Maybe not. But Definitely not sort of.
This post explains it quite well: http://www.andrewnacin.com/2010/09/26/csrf-twitter/
Essentially, just create one or more iframes, with the iframe source set to http://twitter.com/share/update?status=WTF+PAYLOAD
As long as you're logged into Twitter via the web, it will auto-post that update without any request for permission from you.
Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
Or you could install this GM script which expands them to the real URL without actually loading it.
Dilbert RSS feed
Next up: Twitter worms that discuss Natalie Portman naked and petrified, GNAA trolls and of course the classic penis bird.
People replying to my sig annoy me. That's why I change it all the time.