Wednesday, August 26, 2009

Massive Twitter Security Problem Not Resolved Just Yet

Yesterday in the United Kingdom-based SEO expert, David Naylor addresses in detail the cross site Twitter made the task of programming weaknesses that allowed him to put JavaScript code in Twite] by simply adding some code in the field of software developers are usually software products to connect to the Internet. All kinds of destructive things that people have done the process errors, such as the theft of session cookies, cream, or even aware of Twitter visitors with malicious software, so it is safe to say that he was on a large scale security threat.

Of course, when it comes to Twitter transferred to the patch to prevent such problems from bad things happening. John Adams work even in the blog comments Twitter sNaylor on the hole was closed shortly after the release of a message is sent.

Well, not quite.

[Naylor blog post today in yesterday with the person who is still working correctly claim that it is operational. Just like the establishment of a Twitter account almost constant, for which reason (harm) dialog box when you count the link from the site. May soon twitter account suspension, such as self-created fantasy Naylor for the first time point of view, so I included a picture of what happens when you visit the profile at the top of this post.

Naylor says:

With a few minutes, a person with little technical knowledge to create software Twitter '[Twite, and began to send. Using the following simple guidelines, it can be arranged so that users can see Twitter as one of those tweets] - which are logged on to Twitter - can be taken into account.

Imagine for a moment. Just visit one of the [Twite, and can be in your browser to run it, and simulation to do something that your browser can perform. It may just give your site pornographic May for? Or perhaps to delete all words [tweet? Send a message to all your friends? Maybe all of his followers, or worse, just delete the information you need to log in to your account to another site to someone who can use their leisure time.

I find it totally unacceptable that engineers Twitter, and never in contact with Naylor for more information on the work sufficient to solve the problem, which is rightly described by an SEO consultant shame. Instead, it was alleged that she had tried do not really want to achieve stability in the big picture of what potential security risks are:

The idea is to stop putting the consolidation of space in the address box. Distance. In addition, everything else is fair game.

It is important to note that you probably will be safe when you use any third-party Twitter client for your needs, however, we recommend using more stop and visit the Web site of your favorite Twitter for the next few days. Is there any business, be sure to click on the link: Twitter profile that do not know, even when someone you know and trust to be around and associated programs looking abroad suspicious of practical use to remove the tweet].

No comments:

Post a Comment