Washington23 »Software
Print

Twitter onMouseOver flaw poses huge risk to users, is being actively exploited

Filed under: Security
Sophos Labs' Graham Cluely posted this morning about a nasty little Twitter security flaw that is being actively exploited. Twitter apparently doesn't block onMouseOver JavaScript code, which (you guessed it!) kicks in when your mouse pointer passes over a specially crafted link.

What happens next is up to the creator. It could be something harmless like the alert box you see above, or it could just as easily be a rogue antivirus pop-up or some nasty porn site. Again, you don't need to click — you simply have to mouse over a link. As Cluely points out, all Twitter really needs to do is block the OnMouseOver text from being displayed.

TweetDeck reminds users that this exploit doesn't affect third-party clients. Unless you're using twitter.com, you should be totally safe.

At this point, probably 70% of the users I question about how they got an infection are telling me that they were fine until they clicked something from a friend on Facebook or Twitter. I'm starting to think those two sites are going to play cat-and-mouse with Adobe Reader and the Flash Player plug-in for the “who can cause the most malware infections” crown.

update: Twitter responded in a hurry, and the exploit has already been patched.Twitter onMouseOver flaw poses huge risk to users, is being actively exploited

Fuente: Download Squad

No comments

Leave a comment

Image Navigator

Sprint-Branded Motorola XOOM Image SurfacesAMOLED vs LCD – Can the Naked Eye Tell the Difference?Gas Outlook Could Deflate Reliance SharesMotorola Droid X2 Gets its First Custom ROMSamsung Galaxy Apollo Now Available at T-Mobile UK for a 20 Pound Unlimited Data Tariff[Review] Resistance 3Prime Minister Bids Farewell to Dinesh TrivediLG Optimus 3D and Sony Ericsson Xperia Play Priced and Dated for UK on Play.comHotmail Co-Founder Seeks Next Hit in Free SMSCreepy app uses Twitter and Flickr data to track anyone on a mapUndead Nightmare Coming Oct. 26thIndanapolis Colts 2012 Mock Draft: Full 7-Round LookTendulkar to India’s Parliament, Really?Worms brings classic trajectory warfare to webOSTendulkar Shorlisted for Cricketer of the YearNext Version of Android To Be Named “Jelly Bean?”Comprehensive 4-Week Learning Plan For The EVO 4G Launch, Early Prices OutedBlake Lewis At The Top Of Billboard Dance ChartRB Sit Start Week 14: James Starks on the RiseGoogle Introduces Same-Day Shopping to Compete with eBay and AmazonNew Hitachi Batteries Promise Ten-Year LifeWeek 11 IDP Rankings-LB: Start Navorro Bowman & Watch Perry Riley[App Review] FaceLock for Apps protects your apps, brings Face Unlock to GingerbreadBlackBerry 10 Could Be Too Little, Too LateBeauties of the Sea: Behold the World’s Finest SuperyachtsObama, Romney Campaigns Adopt Mobile Payments For DonationsRecord Setting Electric Airplane Breaks 200 MPH Barrier For First TimeAuslogics Disk Defrag 3.2 gets smarter, faster