LZ1
1
Looks like a new cross site scripting vuln just came out…
If you mouse over a certain message it will execute javascript.
Those of you how are following me on twitter there is a non malicious example on my page
For those of you with Firefox I would install NoScript and block all scripts from Twitter.
Fry
2
Is this on twitter.com? I assume it doesn’t work on cell phone apps, tweetdeck, etc?
LZ1
3
This only effects the the website version…
3rd party twitter clients tweetdeck etc are fine…
Wow…very interesting…apparently your retweets dont show up on TweetDeck.
LZ1
5
lol this bug is going to fuck a lot of people on twitter up today
Now running no script on twitter…thanks for the heads up.
<EDIT>
And Gizmodo now has the word:
boxxa
8
I am gonna mouseover every link I find
LZ1
9
11k infections a minute :lol:
---------- Post added at 09:47 AM ---------- Previous post was at 09:43 AM ----------
Someone changed it to make the whole page a mouse over so your pretty much fucked
good thing i thought twitter was retarded and never went on it, im safe.
its only time till it hits facebook though, then im fucked.
LZ1
14
It has nothing to do with facebook…
thanks for the useful input however.
no worries, we are confident that sherlock can crack this case!!
i very much doubt the case, seeming as i got that name for something so very stupid that i said a long time ago
bing
17
LZ, why would someone do this? Do they make money off the spam-advertising or is it just the thrill of the hack?
LZ1
18
Most of what is going on is harmless…Its just changing the status and spreading.
However it has been used to spam products…you could technically use it to hijack/backdoor PCs.
to what? steal peoples info on their computers?
Fry
20
Bahaha the whitehouse twitter got it.