TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How to send DMs on Twitter without permission

167 pointsby broddover 11 years ago

9 comments

chazover 11 years ago
&gt; I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn&#x27;t reward &quot;bounty hunters&quot;.<p>Companies without bug bounties don&#x27;t deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn&#x27;t sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don&#x27;t think they should be mandatory.<p><a href="https://about.twitter.com/company/security" rel="nofollow">https:&#x2F;&#x2F;about.twitter.com&#x2F;company&#x2F;security</a>
评论 #6907473 未加载
评论 #6909753 未加载
评论 #6910034 未加载
jxfover 11 years ago
People in various forums (a couple on HN, SO, Egor&#x27;s blog, Twitter itself) seem to be saying something like &quot;this isn&#x27;t really a bug&quot;.<p>It&#x27;s definitely a bug. Twitter requires clients to ask for the DM permission before they can send DMs. With Egor&#x27;s approach, clients can privilege-escalate themselves to send DMs even if they never asked for that permission (although they still need to be authorized to send tweets).<p>Also, even worse, Twitter doesn&#x27;t consider it a bug, according to the person who originally reported it (who was not Egor): <a href="https://twitter.com/DaKnObCS/status/411869431036653568" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;DaKnObCS&#x2F;status&#x2F;411869431036653568</a><p>And here&#x27;s a response from Ben Ward, the Twitter web lead: <a href="https://twitter.com/benward/status/411924515459850240" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;benward&#x2F;status&#x2F;411924515459850240</a>
评论 #6907868 未加载
评论 #6907726 未加载
评论 #6907554 未加载
gkobergerover 11 years ago
This is the same guy who hacked GitHub (and Rails) with the multiple assignment hack, among other things.
评论 #6907238 未加载
评论 #6907333 未加载
edentover 11 years ago
It only allows you to send DMs to those users you can already message - which is a small mercy.<p>This part of Twitter&#x27;s &quot;Get Better&quot; problem - where they&#x27;ve allowed SMS commands to be activated via non-SMS interfaces - <a href="http://techcrunch.com/2012/05/26/twitter-get-better/" rel="nofollow">http:&#x2F;&#x2F;techcrunch.com&#x2F;2012&#x2F;05&#x2F;26&#x2F;twitter-get-better&#x2F;</a><p>Of course, it doesn&#x27;t help that Twitter&#x27;s permissions system is really poorly thought out. An app which only wants to read your Tweets also has WRITE access as well.
评论 #6907644 未加载
xs_kidover 11 years ago
Isn&#x27;t a bug according to twitter employers:<p><a href="http://twitter.com/jmhodges/status/411975535703511040" rel="nofollow">http:&#x2F;&#x2F;twitter.com&#x2F;jmhodges&#x2F;status&#x2F;411975535703511040</a>
bcardarellaover 11 years ago
the &#x27;d&#x27; syntax for sending DMs has been around from nearly the beginning (or from the actual beginning?) of Twitter. That in itself is not a bug. However, Twitter should be stripping that leading &#x27;d&#x27; from anything that is reposting or from a 3rd party OAauth session.
评论 #6907191 未加载
评论 #6907265 未加载
adelevieover 11 years ago
Not sure how many hours go into finding these sorts of vulnerabilities, but his rate of $150&#x2F;hour[1] seems like a steal compared to the lost revenues he can prevent.<p>[1] <a href="http://www.sakurity.com/" rel="nofollow">http:&#x2F;&#x2F;www.sakurity.com&#x2F;</a>
评论 #6909190 未加载
jcutrellover 11 years ago
This is in line with a long laundry list of horribleness about user experience as related to DMs in my opinion. They don&#x27;t work as expected, and quite honestly to me it feels like Twitter is running a campaign to destroy peoples&#x27; love of the DM in search of a Solution, maybe in preparation for a dm 2.0 or something.<p>Some of the experience elements of DM have been fixed on the iPhone, but last I checked, the problems on web desktop made me so annoyed that I stopped using DMs altogether.
评论 #6907690 未加载
mergyover 11 years ago
Come over to App.net. It will be a while before the masses ruin that.<p>Free invite link &gt;&gt; <a href="https://join.app.net/from/fjjgdclsjq" rel="nofollow">https:&#x2F;&#x2F;join.app.net&#x2F;from&#x2F;fjjgdclsjq</a>
评论 #6907354 未加载