Breaking News

ASRock Introduces Its First Taichi Flagship Monitor Lineup RICOH announces GR IV 30th Anniversary Edition Kit Samsung Begins Official Rollout of One UI 9 Canon announces EOS R8 Mark II Razer Unleashes the Kraken V4 X Sensa HD Haptics

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed

Search form

Twitter Resolves  "onMouseOver" Flaw

Twitter Resolves "onMouseOver" Flaw

Enterprise & IT Sep 22,2010 0

Twitter on Tuesday was notified of a security exploit which was immediately fixed. However, some time later a related issue came up tied to hovercards, which was also fixed. The security exploit that caused problems was caused by cross-site scripting (XSS). Cross-site scripting is the practice of placing code from an untrusted website into another one. In this case, users submitted javascript code as plain text into a Tweet that could be executed in the browser of another user.

Twitter discovered and patched this issue last month. However, a recent site update (unrelated to new Twitter) unknowingly resurfaced it.

Early on Tuesday, a Twitter user noticed the security hole and took advantage of it on Twitter.com. First, someone created an account that exploited the issue by turning tweets different colors and causing a pop-up box with text to appear when someone hovered over the link in the Tweet. This is why folks are referring to this an "onMouseOver" flaw -- the exploit occurred when someone moused over a link.

Other users took this one step further and added code that caused people to retweet the original Tweet without their knowledge.

This exploit affected Twitter.com and did not impact the company's mobile web site or mobile applications. The vast majority of exploits related to this incident fell under the prank or promotional categories, Twitter said. Although users may still see strange retweets in their timelines caused by the exploit, the company is not aware of any issues related to it that would cause harm to computers or their accounts. Twitter says that there is no need to change passwords because user account information was not compromised through this exploit.

"We?re not only focused on quickly resolving exploits when they surface but also on identifying possible vulnerabilities beforehand. This issue is now resolved. We apologize to those who may have encountered it," Twitter added.

Tags: Twitter
Previous Post
BlackBerry Tablet Device May Launch Next Week
Next Post
Sony's Slim External BDX-S500U Blu-ray Burner Released in the United States

Related Posts

  • Elon Musk to Acquire Twitter

  • Twitter Marks President Trump's Tweet With Tag Warning About "Violence"

  • Twitter's New Settings Let You Choose Who Can Reply to Your Tweet

  • Twitter to Let Employees Work From Home For Ever

  • Twitter Launches Labels to Warn On Misleading COVID-19 Information

  • Twitter to Start Warning Users That Post Offensive Replies

  • Twitter Reports Small Revenue As Advertising Business Hit By Covid-19

  • Twitter to Make Data Available COVID-19 Tweets to Researchers

Latest News

ASRock Introduces Its First Taichi Flagship Monitor Lineup
Consumer Electronics

ASRock Introduces Its First Taichi Flagship Monitor Lineup

RICOH announces GR IV 30th Anniversary Edition Kit
Cameras

RICOH announces GR IV 30th Anniversary Edition Kit

Samsung Begins Official Rollout of One UI 9
Smartphones

Samsung Begins Official Rollout of One UI 9

Canon announces EOS R8 Mark II
Cameras

Canon announces EOS R8 Mark II

Razer Unleashes the Kraken V4 X Sensa HD Haptics
Consumer Electronics

Razer Unleashes the Kraken V4 X Sensa HD Haptics

Popular Reviews

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

The Quiet Technology Behind the Spin

The Quiet Technology Behind the Spin

SoundPeats Cove Pro

SoundPeats Cove Pro

Akaso Brave 8 Lite

Akaso Brave 8 Lite

Kioxia Exceria Plus G3 512GB microSD

Kioxia Exceria Plus G3 512GB microSD

be quiet! Dark Perk Mice

be quiet! Dark Perk Mice

SoundPeats C30

SoundPeats C30

XbotGo Chamaleon

XbotGo Chamaleon

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed