4 ms·
Relatively harmless as viruses go, so I have to admit to being a bit excited at watching a little bit of internet history unfold. EDIT: mea culpa, you're quite
by rsbrown 16y ago
Relatively harmless as viruses go, so I have to admit to being a bit excited at watching a little bit of internet history unfold.
EDIT: mea culpa, you're quite right -- the potential for this is disastrous in terms of CSRF attacks and so on. I was thinking about this particular implementation that appeared to simply be propagating itself.
- bl4k 16y agonot harmless at all? this can do so much damage because you can run javascript in the context of the users session. some ideas for payloads: * login as that user by sending yourself their session token * scrape email addresses * follow a spam account * popup an affiliate site * trigger a download or one of the new flash exploits to gain access to the local system your code has to fit within 140 chars, but you can use the libraries that Twitter has included in the page (like $()) to grab elements and make Ajax calls to their backend. This is a shocker.
- robryan 16y agoWill the session token work just like that? Each session might be tied to a specific IP address or something.
- bruceboughton 16y agoWhen I last checked about 2 years ago, Twitter had woeful session management.
- user24 16y agotying things to specific IP address isn't a good idea. Some ISPs rotate outbound IP addresses on a per-connection basis. As in, when you refresh, you might be coming from a different IP. I think AOL first did this some years ago. It's a real shame.
- andreyf 16y agoWho got harmed?
- mikecane 16y agoMy Twitter page has a frikkin overlay on it now, preventing its use. I define harm as not being able to use Twitter due to a malicious act. Sure, I haven't lost a leg, but it's a PITA. I'll probably have to change my password yet again too.
- konad 16y agoWith the right payload, you won't know you've been affected via Twitter.
- eli 16y agoI'm pretty sure I could load an external JS file in 140 chars, so there's effectively no limit.
- statictype 16y agohttp://api.jquery.com/jQuery.getScript/ http://api.jquery.com/jQuery.getScript/ That's pretty much all you need. About 15 chars + length of the script url. So yeah, there's effectively no limit.