TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users

48 pointsby sliggityover 14 years ago

8 comments

stanleydrewover 14 years ago
After reading this I have no idea how he actually discovered the vulnerability, aside from a handwavy statement about messing with form input.<p>Most of the writeup is just a narrative about what he saw and who he talked to afterwards. I'm a little disappointed. I was hoping for more technical detail.
评论 #2175566 未加载
nbpooleover 14 years ago
I need to get better at creating these kinds of titles for my vulnerability writeups :P
评论 #2175302 未加载
arthurgibsonover 14 years ago
"All support tickets – at the time, 1.5+ million! – were exposed"<p>* Was this actually 1.5M users or just tickets? Thats a lot of upset people if so.
评论 #2174934 未加载
gyardleyover 14 years ago
Wait, account passwords were visible?<p>Was this a case of account passwords being sent to Twitter Support by users - 'hey, I can't login, my password is bigclown' - or does Twitter Support have a way to access the user's actual password?<p>If it's the latter, that's a time bomb waiting to go off.
评论 #2175216 未加载
erikabeleover 14 years ago
This reminds me of some flaw with Skype's billing system which allowed me to download invoices for virtually every paying business customer just by replacing some chars in a URL. The invoices included a lot of personal details together with various bank account &#38; phone numbers.<p>Took me 8 months to get someone at Skype to acknowledge the issue; to my knowledge it was never escalated. Wouldn't be surprised if it's still there...
kmccarthover 14 years ago
Twitter Support gets about 100-200 tickets per hour
评论 #2174613 未加载
jdp23over 14 years ago
Good writeup.<p>Was the vulnerability in Zendesk or in how Twitter had configured the system?
评论 #2174963 未加载
tptacekover 14 years ago
You usually don't have to write headlines like "1.5M users compromised!" to get people to fix trivial web flaws. Also, before asking VC's and posting public Twitter messages and spending two days trying to track down a security contact, try mailing "security@" <i>first</i>; as you discovered, that sensible default generated an immediate response.<p><i>Edited out "not '96 anymore", the word "breathless", and my assessment of his effort to track down security@ as "hinky"; I wasn't happy with the tone of this comment in retrospect either.</i>
评论 #2175374 未加载
评论 #2175354 未加载