PDA

View Full Version : [HIB]Twitter XSS Vulnerability Possibly Exploited



newsbot
30-06-2010, 02:12 AM
A Twitter cross-site scripting (XSS) vulnerability reported late last week was quickly fixed by the website's security staff. The flaw might have been abused in an earlier attack that affected hundreds of Twitter accounts. The persistent XSS bug was disclosed by an Indonesian grey hat hacker going by the online moniker of "H4x0r-x0x," who demoed it on his own Twitter account. People who visited his profile were prompted with several consecutive JavaScript alert windows giving credit to the security enthusiast. After the alerts the whole page modified to display a matrix-like background.According to Daniel Kennedy of Praetorian Security Group, who published an in-depth analysis of the proof-of-concept attack, the hacker left a message reading "there is no crime here! I just create To smarten view my Twitter profile," suggesting that his intentions were not malicious.

**Hidden Content: Check the thread to see hidden data.**