RSS feed for About Kris AbelContact Kris

RSS feed for About Kris AbelKris Abel on Twitter

FeedRSS Feed

Share |
September 21, 2010 09:51  by Kris Abel

If you sign into your Twitter account directly through the Twitter.com website, be warned that an annoying hack is rapidly spreading across the network. Strange messages containing what at first looks like a link to a webpage the concern. These "mouseover" links actually contain instructions that cause annoying pop-up windows to appear and is triggered merely by you touching the link with your mouse cursor, there's no need to click on it. Once your account is hacked in this manner it begins to tweet and retweet copies of the malicious link. Both the new Twitter.com design and the old are susceptible, but if you use a third-party client or mobile application such as Tweetdeck, Twitterific, or even Twitter for BlackBerry, iPhone, or iPad you're immune to the attack. Twitter is no doubt scrambling to respond to issue and deliver a fix, but has yet to make a public statement. 

Update: Twitter says they have resolved the issue. Here's their statement from the Twitter Status page:

"We’ve identified and are patching a XSS attack; as always, please message @safety if you have info regarding such an exploit.We expect the patch to be fully rolled out shortly and will update again when it is.Update (6:50 PDT, 13:50 UTC): The exploit is fully patched."

Screenshot by Sophos. 

Add comment


(Will show your Gravatar icon)  
Click to change captcha
biuquote
  • Comment
  • Preview
Loading