Categories: GeneralSecurityWeb

Twitter hackers hit rollover jackpot

If you’re a Twitter user, it’s best to steer clear of the main site for the time being. A cross-site scripting error has led to everything from whimsical fun and games to full-on hacking attempts.

The site itself hasn’t been hacked as such, but users both fair and foul have been exploiting a flaw that allows links posted at Twitter.com to be active just from a rollover rather than a click, using the old-school Ja vascript onMouseOver function.

If you remember this from the early days of web page building, you’ll probably remember hooking up a link to produce a pop-up message to read “you smell” when the mouse rolls over it. And there’s certainly plenty of that type of japery going on, but some of the abuse is more serious.

As well as spammers exploiting the bug to produce pop-up advertising, those of a more malicious nature have been setting links to open automatically. That’s being done by using a URL shortener to get the full link in but still allow the javascript command to be inserted in a way that isn’t filtered out by the Twitter site.

A post on the account of Sarah Brown, the wife of the former British Prime Minister, is reported to have redirected readers to a Japanese hardcore porn site. And there are also reports of rollovers links sending users straight to malware sites that, for example, use a worm to hijack the Twitter account and post more links (which is presumably what happened to Brown.)

The issue doesn’t appear connected to the new Twitter.com homepage design that is being rolled out to users: it’s affecting visitors to both the original and revised site. Third-party applications are unaffected.

If you really feel the need to use a web version of Twitter, the version formatted for mobile devices (mobile.twitter.com) appears to be safe at the moment, with the infected links simply appearing as a string of code. Visting that site is also a quick way to see how rapidly the problem is spreading among your contacts.

(Picture credit: Sophos)

JLister

Recent Posts

Costco’s Hot Dog Economics: Bun-derful Bargains or Frank-ly a Loss Leader?

https://youtu.be/twUK5YreLWk?si=SZGqB6HsbkYaGKyr Ever wondered why the price of Costco's legendary hot dogs has remained unchanged at…

21 mins ago

How logic alone may prove that time doesn’t exist

StunningArt/Shutterstock Matyáš Moravec, University of St Andrews Modern physics suggests time may be an illusion.…

1 hour ago

RIP John Trimble: The Man Who Saved Star Trek from Cancellation

In a galaxy far, far away from the clutches of cancellation, a hero quietly worked…

3 hours ago

Today’s Hottest Deals: X-Men ’97 Magneto Premium Helmet, Bose QuietComfort Headphones, Apple Watch Series 9, Apple AirTag, and More!

For today’s edition of “Deal of the Day,” here are some of the best deals…

3 hours ago

Nat 20 [Comic]

[Source: @colmcomics]

4 hours ago

Sweet Talk or Cringe-Worthy: The Science of Cheesy Pet Names

https://youtu.be/KJpYWOJNVGY?si=vsu_6JYvYYO9VBpH Ever wondered why we use those adorable yet cringey words for our loved ones?…

4 hours ago