Twitter Vulnerability Discovered by Australian Teenager

On the subject of the Twitter brouhaha from yesterday, apparently the vulnerability in the site’s code that led to all the pop-ups, worms, and general merriment enjoyed by spammers and hackers was discovered by a 17-year-old Australian named Pearce Delphin.

Apparently Delphin simply posted JavaScript code inside a tweet that caused a pop-up window whenever someone hovered over the posted text. In an interview with the AFP, Delphin said the following:

“I did it merely to see if it could be done… At the time of posting the tweet, I had no idea it was going to take off how it did. I just hadn’t even considered it…

After that, it seems like some of my followers realized the power of this vulnerability, and within a matter of minutes scripts had taken over my timeline.”

The ability to run code in this manner could have theoretically led to some serious privacy breaches, such as writing code that steals users’ account credentials. However, “The problem was being able to write the code that can steal usernames and passwords while still remaining under Twitter’s 140 character tweet limit,” said Delphin.

Twitter has since patched up the vulnerability, which Delphin said they knew about for “months.” Twitter’s official stance is that its engineers “discovered an patched this issue last month. However, a recent site update (unrelated to new Twitter) unknowingly resurfaced it.”

More on Techand:

Twitter Has Been Hacked

What Does The New Twitter Actually Do? A Picture Guide For The Updated Features

A Radically New Twitter.com

Related Topics: hacks, internet, security, Gadgets, Twitter
  • Latest on Techland

    Nvidia

    Nvidia’s Kai Brings Hope for $199 Quad-Core Tablets

    Nvidia has a plan to make cheap Android tablets a lot more powerful. The company will launch a platform this year called “Kai” that will let device makers bring quad-core tablets to market for $199.

    The Top 7 Women On YouTube: Meet The Site's Biggest Female StarsHuffington Post

    gavels

    Jury: Google Didn’t Infringe on Oracle Patents

    A federal jury in San Francisco has decided that Google didn’t infringe on Oracle’s patents when the search company developed its popular Android software for mobile devices.

blog comments powered by Disqus