<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.14612-</id>
  <updated>2011-08-16T17:27:55Z</updated>
  <title>Comments for Twitter Vulnerability: Mutating Fast and More on the Way</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=14612" title="Twitter Vulnerability: Mutating Fast and More on the Way" />
    <published>2009-04-12T16:48:45Z</published>
    <updated>2009-04-12T17:05:36Z</updated>
    <title>Twitter Vulnerability: Mutating Fast and More on the Way</title>
    <summary>Just hours after Twitter began removing the first cross-site scripting vulnerability that hit its site this weekend, a new modified strain has been found, and according to F-Secure, it&apos;s not the last one we&apos;re likely to see over the next few days. &quot;This is not over. There&apos;s going to be quite a few modified Twitter...</summary>
    <author>
      <name>Lidija Davis</name>
      
    </author>
    
    <category term="NYT" />
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="twitter_apr_09.jpg" src="http://www.readwriteweb.com/images/twitter_apr_09.jpg" width="120" height="54" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" />Just hours after Twitter began removing the first cross-site scripting vulnerability that hit its site this weekend, a new modified strain has been found, and according to <a href="http://www.f-secure.com/weblog/archives/00001653.html">F-Secure</a>, it's not the last one we're likely to see over the next few days.</p>

<p>"This is not over. There's going to be quite a few modified Twitter worms for a day or two. Be careful in Twitter, don't view profiles, don't follow links. It's beautiful outside, maybe go for a walk instead?" Mikko said on the F-Secure blog earlier today.</p>]]>
      <![CDATA[<p>According to <a href="http://www.bnonews.com/news/242.html">Breaking News</a>, Mikeyy Mooney, the 17 year-old owner of StalkDaily.com, has reportedly admitted responsibility for yesterday's attack.</p>

<blockquote>"I am the person who coded the XSS which then acted as a worm when it auto updated a users profile and status, which then infected other users who viewed their profile. I did this out of boredom, to be honest. I usually like to find vulnerabilities within websites and try not to cause too much damage, but start a worm or something to give the developers an insight on the problem and while doing so, promoting myself or my website."</blockquote>

<p>We wrote about StalkDaily <a href="http://www.readwriteweb.com/archives/stalkdaily_a_new_twitter_virus_on_the_loose.php">yesterday</a>, and last night Twitter pointed out on its <a href="http://status.twitter.com/post/95332007/update-on-stalkdaily-com-worm">status blog</a> that it has "taken steps to remove the offending updates and to close the holes that allowed this 'worm' to spread."  The offending code can be found at <a href="http://gist.github.com/93782">GitHub</a> as noted by <a href="http://www.mrspeaker.net/">Mr Speaker</a> who left a message in our <a href="http://www.readwriteweb.com/archives/stalkdaily_a_new_twitter_virus_on_the_loose.php#comment-133069">comments</a>, and a postmortem of yesterday's vulnerability can be found on the <a href="http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/">DCortesi</a> blog.</p>

<p>Clearly Mikeyy is still bored as the new version is now making its way across the Twitterverse, tweeting comments such as: "Man, Twitter can't fix shit. Mikeyy owns :)"  </p>

<p>So if you see a tweet with the word Mikeyy - don't click on it.</p>

<p>F-Secure is reporting that all of these attacks are Javascript based and suggests turning it off.  You can find instructions on how to turn off JavaScript in the four main browsers; Firefox, Internet Explorer, Safari and Opera at <a href="http://www.tucows.com/article/1690">Tucows</a>.</p>

<p>If you need to remove Mikeyy, <a href="http://twittercism.com/remove-mikeyy/">Twittercism</a> walks you through in six easy steps.</p>

<p>We'll keep you updated as the day progresses.</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:192583</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c192583" />
    <title>Comment from mahesh mehra on 2010-02-24</title>
    <author>
        <name>mahesh mehra</name>
        <uri>http://www.3generationsecurity.co.cc</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.3generationsecurity.co.cc">
        <![CDATA[<p>Twitter is a very vulnerable web.i have found 2 vulnerabilities in twitter and informed to twitter administrator & CERT india.<br />
www.3generationsecurity.co.cc<br />
</p>]]>
    </content>
    <published>2010-02-24T12:47:12Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:180965</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c180965" />
    <title>Comment from Super Bowl 44 live stream on 2010-01-17</title>
    <author>
        <name>Super Bowl 44 live stream</name>
        <uri>http://superbowl44livestream.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://superbowl44livestream.blogspot.com">
        <![CDATA[<p>Twitter accounts of celebrities are being hacked these days.</p>]]>
    </content>
    <published>2010-01-17T14:42:20Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:160210</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c160210" />
    <title>Comment from Painters Glasgow on 2009-09-29</title>
    <author>
        <name>Painters Glasgow</name>
        <uri>http://www.yourbuildingpartner.co.uk</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.yourbuildingpartner.co.uk">
        <![CDATA[<p>"This is not over. There's going to be quite a few modified Twitter worms for a day or two. Be careful in Twitter, don't view profiles, don't follow links. It's beautiful outside, maybe go for a walk instead?" Mikko said on the F-Secure blog earlier today.</p>

<p>It is actually a great advice even if Twitter is worm-free. Why would people want to follow others online, while they can do it in real life, they only need to be a little more careful ;)</p>]]>
    </content>
    <published>2009-09-29T12:22:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133292</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133292" />
    <title>Comment from Kaspars on 2009-04-13</title>
    <author>
        <name>Kaspars</name>
        <uri>http://twizt.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://twizt.com/">
        <![CDATA[<p>FAIL worm cartoon :) <a href="http://mindcream.com/failworm/" rel="nofollow">http://mindcream.com/failworm/</a></p>]]>
    </content>
    <published>2009-04-13T23:21:58Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133173</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133173" />
    <title>Comment from Runescape gold on 2009-04-13</title>
    <author>
        <name>Runescape gold</name>
        <uri>http://www.gaiasale.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.gaiasale.com">
        <![CDATA[<p>We'll keep you updated as the day progresses.</p>]]>
    </content>
    <published>2009-04-13T08:00:14Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133155</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133155" />
    <title>Comment from caligulazhang on 2009-04-12</title>
    <author>
        <name>caligulazhang</name>
        <uri>http://customs-data.com.cn</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://customs-data.com.cn">
        <![CDATA[<p>Thank you~~   Welcome to participate in the discussionwww.customs-data.com.cn/tradeinformation/topease.htm </p>]]>
    </content>
    <published>2009-04-13T05:16:29Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133150</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133150" />
    <title>Comment from don hon on 2009-04-12</title>
    <author>
        <name>don hon</name>
        <uri>http://na</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://na">
        <![CDATA[<p>Twitter just sucks my balls so hard</p>]]>
    </content>
    <published>2009-04-13T04:48:53Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133148</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133148" />
    <title>Comment from alantanblog on 2009-04-12</title>
    <author>
        <name>alantanblog</name>
        <uri>http://www.alantanblog.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.alantanblog.com">
        <![CDATA[<p>I need to update my AV fast then</p>]]>
    </content>
    <published>2009-04-13T04:29:12Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133144</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133144" />
    <title>Comment from 面经 on 2009-04-12</title>
    <author>
        <name>面经</name>
        <uri>http://www.jobsphere.cn/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.jobsphere.cn/">
        <![CDATA[<p>Hehe, there will be more to come?</p>]]>
    </content>
    <published>2009-04-13T04:13:28Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133143</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133143" />
    <title>Comment from biggreenape on 2009-04-12</title>
    <author>
        <name>biggreenape</name>
        <uri>http://www.biggreenape.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.biggreenape.com">
        <![CDATA[<p>I might be misinformed, but these types of attacks illegal?  If this specific situation is not illegal, what's the loop hole?</p>]]>
    </content>
    <published>2009-04-13T03:44:06Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133130</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133130" />
    <title>Comment from www.friends-finder.ws on 2009-04-12</title>
    <author>
        <name>www.friends-finder.ws</name>
        <uri>http://friends-finder.ws</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friends-finder.ws">
        <![CDATA[<p>I thing this attack is welcome to Twitter because in this way will enhance the safety measures.</p>]]>
    </content>
    <published>2009-04-12T20:20:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133129</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133129" />
    <title>Comment from Wesley on 2009-04-12</title>
    <author>
        <name>Wesley</name>
        <uri>http://www.improvingtheweb.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.improvingtheweb.com">
        <![CDATA[<p>Err, are you sure this is correct? Can't they just htmlspecialchar() all input (or output..) - Don't see any way anyone would be able to sneak past that.. mutations or not.</p>]]>
    </content>
    <published>2009-04-12T20:17:44Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133126</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133126" />
    <title>Comment from Portable Color Scanner on 2009-04-12</title>
    <author>
        <name>Portable Color Scanner</name>
        <uri>http://portablecolorscanners.blogspot.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://portablecolorscanners.blogspot.com/">
        <![CDATA[<p>I think it is inevitable when you start to gain traction</p>]]>
    </content>
    <published>2009-04-12T20:07:13Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133117</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133117" />
    <title>Comment from erken rezervasyon on 2009-04-12</title>
    <author>
        <name>erken rezervasyon</name>
        <uri>http://www.nettentatil.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.nettentatil.com">
        <![CDATA[<p>Thank You..</p>]]>
    </content>
    <published>2009-04-12T18:54:07Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14612-comment:133112</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14612" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/twitter_vulnerability_mutating_fast_and_more_on_th.php#c133112" />
    <title>Comment from Scott Schiller on 2009-04-12</title>
    <author>
        <name>Scott Schiller</name>
        <uri>http://schillmania.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://schillmania.com/">
        <![CDATA[<p>All user-provided content must be sanitized before being stored (and/or redisplayed) to deter cross-site scripting attacks.</p>

<p>In this case there have been two forms of XSS; via &lt;script&gt; in profile URLs, and within the limited amount of custom CSS (link and background colors) a user can provide for their profile page.</p>

<p>This form of XSS is very similar to the "Samy is my friend" MySpace worm from several years back.</p>

<p>For Firefox users, the "NoScript" extension helps to deter XSS.</p>]]>
    </content>
    <published>2009-04-12T17:34:42Z</published>
  </entry>

</feed>
