Rabu, 13 Oktober 2010

Write your own Twitter.com XSS exploit

So it seems the new twitter.com has a “virus” going around. Few minutes ago my twitter stream filled up with strange jQuery calls so I looked into it. Apperantly the new Twitter website is colunerable to a simple SQL-Injection like attack. It’ll just spit out to the page whatever HTML code you write on your status… So, the exploit work like this:Step 1:User writes the following status line:http:/

Tidak ada komentar:

Posting Komentar