• Home
  • What is RSS
  • News & Reviews
    • Future Technology
    • Editors Choice
    • Gadget Reviews
    • CNN Tech
    • WP Technology
  • Site Map

PostHeaderIcon Tech Menu

Technology
Software
Cisco
Communication
Web Design
Web Hosting
Content Management Systems (CMS)
Search Engine Optimization (SEO)
101 all components amd building pc camera printer canon pixma chromalife 100 commodore 64 competitiors components pc computer games computer skills consulting 101 consulting business digital media digital photography duplex printing games today ink cartridges ip4200 ip4200 cartridges pac man pc case pixma pixma ip4200 pong skills computer consulting business technical computer technical computer skills virus software
business ccna ccna certification ccnp certification cisco cisco articles cisco ccna computer data design hosting internet online pc phone search security server site software system voip web web design web host web hosting web site website wireless
101 all components amd building pc business camera printer ccna ccna certification ccnp chromalife 100 cisco commodore 64 components pc computer consulting 101 consulting business design digital photography hosting internet security server site software web web design web host web hosting web site website
Home News & Reviews WP Technology Faster Forward: Twitter users hit with 'mouse over' hack

Tech Search

PostHeaderIcon Faster Forward: Twitter users hit with 'mouse over' hack

If you were on Twitter's site earlier this morning and saw weird stretches of blacked-out text in other people's updates, I hope you didn't send the cursor over them. But if you fell for this hack and had your Twitter account temporarily hijacke... d, I understand; I probably would have done the same thing myself.

This attack raced through the popular update-sharing service. As Sophos researcher Graham Cluly explained in a blog post, it lured users to "mouse over" snippets of Web code that had been blacked out, then exploited a flaw in the older version of Twitter's site (not the new one launched with a flurry of hype a week ago) to send out a new copy of itself under victims' accounts and sent visitors to some sketchy Japanese porn site.

Because the attack's bait looked so innocuous -- it's not uncommon for Twitter users to play around with funny embedded graphics in their otherwise text-only updates -- many people fell for them. Around Washington, the best known may have been White House press secretary Robert Gibbs; the crestfallen update he sent right after getting suckered appears in the image at right. (Poor guy.)

Twitter quickly posted warnings on its status blog and its "@Safety" Twitter account. About an hour later, it had fixed its old site to close the vulnerability.

Users of the redesigned version of Twitter were not affected, nor were those using mobile versions of the site or such separate applications as TweetDeck or Twitterfall. But because this attack -- in technical terms, a "cross-site scripting" -- took advantage of nothing more complicated than a Web browser's support for JavaScript coding, pretty much everybody else was vulnerable.

Twitter users have reported that they got hit in both Windows and Mac OS X while using the latest versions of generally more secure browsers such as Mozilla Firefox and Google's Chrome. (Weirdly enough, others have told me they weren't affected while running similar software configurations.) An anti-virus program would not have helped, as the attack didn't involve running a separate program.

We're only going to see more of this nonsense as our applications increasingly take the form of Web sites. Web users need to retain a healthy level of suspicion online, and browser developers need to stay on top of these threats. But it's even more important for Web developers to spot and stomp these flaws as soon as they can.

< Prev   Next >
 

Software

  • Finding Photo Editing Software
  • Advanced COM Port Redirector V4...
  • Virus or spyware what's the Dif...
  • StrongBit and 9Rays Partner In ...
  • Password Recovery Toolbox for O...

Search Engine Optimization SEO

  • Tips and Tricks For Using WordP...
  • SEO Tips For Bloggers With Big ...
  • Use an SEO Company to Increase ...
  • Search Engine Optimization in G...
  • How Important Are FAQ Pages For...

Technology

  • The Advantages of Wireless POS ...
  • 5 Desktop Computer Hardware Myt...
  • Technical Staff: Challenge Them
  • The Worst Case Scenario: How To...
  • Power Supply Tips

Web Hosting

  • Web Hosting:Where to Start
  • Having The Best Web Hosting Pla...
  • How to find and use file-hostin...
  • Web Hosting For Internet Market...
  • Web Hosting Affiliate Program S...

Content Management Systems (CMS)

  • How to Use a Free CMS to Power ...
  • Top 6 Advantages of Using A Con...
  • CMS - Build, Deploy, and Mainta...
  • What in the World is a CMS?
  • Does Web 2.0 Make a Difference ...

Web Design

  • Interactive Internet Marketing ...
  • Which Display Resolution is Bes...
  • Are You Content With Your Web A...
  • HOW TO DESIGN A SEARCH ENGINE F...
  • The long and short of gif and j...

Communication

  • SMS Gateway Basics
  • Ringtones are Red Hot
  • VoIP and local phone service
  • MP3 Ringtones - Inject your own...
  • Mobile phones and their Multipl...

Cisco Articles

  • CCNA / CCNP Home Lab Tutorial: ...
  • Passing Your CCNA and CCNP: Con...
  • Cisco CCNA / CCNP Home Lab Setu...
  • Passing The CCNA and CCNP Exams...
  • Cisco CCNA / CCNP Home Lab Tuto...

© raidencomputers.co.uk 2003 - 2010

Web Design Kent by MCGA