I would be careful on Twitter today...

Looks like a new cross site scripting vuln just came out…

If you mouse over a certain message it will execute javascript.

Those of you how are following me on twitter there is a non malicious example on my page

For those of you with Firefox I would install NoScript and block all scripts from Twitter.

Is this on twitter.com? I assume it doesn’t work on cell phone apps, tweetdeck, etc?

This only effects the the website version…

3rd party twitter clients tweetdeck etc are fine…

Wow…very interesting…apparently your retweets dont show up on TweetDeck.

lol this bug is going to fuck a lot of people on twitter up today

Now running no script on twitter…thanks for the heads up.

<EDIT>

And Gizmodo now has the word:

good looks on this

I am gonna mouseover every link I find :slight_smile:

11k infections a minute :lol:

---------- Post added at 09:47 AM ---------- Previous post was at 09:43 AM ----------

Someone changed it to make the whole page a mouse over so your pretty much fucked :slight_smile:

good thing i thought twitter was retarded and never went on it, im safe.

Good for you

great work sherlock!

its only time till it hits facebook though, then im fucked.

It has nothing to do with facebook…

thanks for the useful input however.

no worries, we are confident that sherlock can crack this case!!

i very much doubt the case, seeming as i got that name for something so very stupid that i said a long time ago

LZ, why would someone do this? Do they make money off the spam-advertising or is it just the thrill of the hack?

Most of what is going on is harmless…Its just changing the status and spreading.

However it has been used to spam products…you could technically use it to hijack/backdoor PCs.

to what? steal peoples info on their computers?

Bahaha the whitehouse twitter got it.