TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

XSS in Tweetdeck (don't view in Tweetdeck...)

37 pointsby maaarghkalmost 11 years ago

14 comments

adambardalmost 11 years ago
So apparently this was retweeted by @5SOS, a teen pop band with some 3 million followers, which is why most of the responses are confused teenagers.<p>For some reason this is hilarious to me. Not the pinnacle of responsible disclosure, but no real harm done.
评论 #7879006 未加载
mrspeakeralmost 11 years ago
The replies to that tweet are beautiful. Sometimes you forget that not everyone in the world can recognize a cross-site scripting vulnerability when they see one!
thebossalmost 11 years ago
What&#x27;s sad is that not even wrong security was in place here. They didn&#x27;t even try. There was NO XSS prevention.<p>&lt;script&gt;javascript&lt;&#x2F;script&gt; is the first payload you try when looking for the stupidest XSS you can find....
评论 #7879037 未加载
评论 #7879315 未加载
评论 #7878998 未加载
k-mcgradyalmost 11 years ago
I guess the New York Times uses Tweetdeck[1]. I saw this because several people I follow had retweeted it and the Twitter app notifies you if several of your followers do the same thing. It&#x27;s a useful feature. If Tweetdeck does the same thing it could make this spread really fast.<p>[1] <a href="https://twitter.com/derGeruhn/status/476764918763749376" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;derGeruhn&#x2F;status&#x2F;476764918763749376</a>
DouweMalmost 11 years ago
I wonder if the poster of this &quot;twitter worm&quot; could get in legal trouble for this; it&#x27;s quite similar to the Samy MySpace worm[1] of a decade ago, where the creator was charged with a felony (they plea bargained out).<p>[1] <a href="https://en.wikipedia.org/wiki/Samy_(computer_worm)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Samy_(computer_worm)</a>
评论 #7879434 未加载
blackRustalmost 11 years ago
Looks like it might even be starting to loop around? The Guardian have already scurried an article about it [1].<p>[1] <a href="http://www.theguardian.com/technology/2014/jun/11/twitter-tweetdeck-xss-flaw-users-vulnerable" rel="nofollow">http:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2014&#x2F;jun&#x2F;11&#x2F;twitter-tw...</a>
6thSigmaalmost 11 years ago
A lot of people I follow must use Tweetdeck. This has been retweeted on my feed several times in the last few minutes.
评论 #7878968 未加载
maaarghkalmost 11 years ago
Wonder if it&#x27;s because of the emoji at the end? It&#x27;s HEAVY BLACK HEART, U+2764, e29da4 in hex.
zatkinalmost 11 years ago
&quot;The <i>most powerful</i> Twitter tool for real-time tracking, organizing and engagement.&quot;
评论 #7879265 未加载
basicallydanalmost 11 years ago
39,000 retweets and counting.
rrss1122almost 11 years ago
Someone&#x27;s gonna get in trouble for using an eval in tweetdeck...
sp332almost 11 years ago
Tweetdeck seems to be down now.
评论 #7879184 未加载
tarekmozalmost 11 years ago
Security 101 ?
hybridknightalmost 11 years ago
so fast
评论 #7878947 未加载