Early Bird Gets The Worm

http://a.no/@”onmouseover=”;$(‘textarea:first’).val(this.innerHTML);$(‘.status-update-form’).submit()” style=”color:#666;background:#666;/

When the above is “tweeted” it will create an update that will look like gray bars -

Now anyone who is following you will get the update and if they hover over this tweet they will immediately update their own profile with the same “tweet”. Although this bug specifies that it will trigger on mouse over, from what I have seen it has been triggered by simply viewing the tweet. This seems to only be effecting the actual twitter.com website, so if you are using an application like tweetdeck this bug will not be triggered.

So far the bug seems to be fairly non-malicious but that could change very quickly depending on the time it takes Twitter to fix the issue. To be safe, it may be best to take a break from the “twitterverse” until this blows over.

This entry was posted in Blog, Web Application Security. Bookmark the permalink.