Breaking News

Firewalla App 1.67 Brings Enterprise Wi-Fi, RADIUS, and Advanced AP7 Controls to Small Businesses and Power Users Samsung To Unveil AI Vision Built With Google Gemini at CES 2026 Samsung Unveils New Odyssey Gaming Monitor Lineup COLORFUL Launches iGame GeForce RTX 50 MINI OC Series Graphics Cards for Compact PCs LG Display unveils world’s first 240Hz RGB stripe OLED panel

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Twitter Resolves  "onMouseOver" Flaw

Twitter Resolves "onMouseOver" Flaw

Enterprise & IT Sep 22,2010 0

Twitter on Tuesday was notified of a security exploit which was immediately fixed. However, some time later a related issue came up tied to hovercards, which was also fixed. The security exploit that caused problems was caused by cross-site scripting (XSS). Cross-site scripting is the practice of placing code from an untrusted website into another one. In this case, users submitted javascript code as plain text into a Tweet that could be executed in the browser of another user.

Twitter discovered and patched this issue last month. However, a recent site update (unrelated to new Twitter) unknowingly resurfaced it.

Early on Tuesday, a Twitter user noticed the security hole and took advantage of it on Twitter.com. First, someone created an account that exploited the issue by turning tweets different colors and causing a pop-up box with text to appear when someone hovered over the link in the Tweet. This is why folks are referring to this an "onMouseOver" flaw -- the exploit occurred when someone moused over a link.

Other users took this one step further and added code that caused people to retweet the original Tweet without their knowledge.

This exploit affected Twitter.com and did not impact the company's mobile web site or mobile applications. The vast majority of exploits related to this incident fell under the prank or promotional categories, Twitter said. Although users may still see strange retweets in their timelines caused by the exploit, the company is not aware of any issues related to it that would cause harm to computers or their accounts. Twitter says that there is no need to change passwords because user account information was not compromised through this exploit.

"We?re not only focused on quickly resolving exploits when they surface but also on identifying possible vulnerabilities beforehand. This issue is now resolved. We apologize to those who may have encountered it," Twitter added.

Tags: Twitter
Previous Post
BlackBerry Tablet Device May Launch Next Week
Next Post
Sony's Slim External BDX-S500U Blu-ray Burner Released in the United States

Related Posts

  • Elon Musk to Acquire Twitter

  • Twitter Marks President Trump's Tweet With Tag Warning About "Violence"

  • Twitter's New Settings Let You Choose Who Can Reply to Your Tweet

  • Twitter to Let Employees Work From Home For Ever

  • Twitter Launches Labels to Warn On Misleading COVID-19 Information

  • Twitter to Start Warning Users That Post Offensive Replies

  • Twitter Reports Small Revenue As Advertising Business Hit By Covid-19

  • Twitter to Make Data Available COVID-19 Tweets to Researchers

Latest News

Firewalla App 1.67 Brings Enterprise Wi-Fi, RADIUS, and Advanced AP7 Controls to Small Businesses and Power Users
Enterprise & IT

Firewalla App 1.67 Brings Enterprise Wi-Fi, RADIUS, and Advanced AP7 Controls to Small Businesses and Power Users

Samsung To Unveil AI Vision Built With Google Gemini at CES 2026
Consumer Electronics

Samsung To Unveil AI Vision Built With Google Gemini at CES 2026

Samsung Unveils New Odyssey Gaming Monitor Lineup
Consumer Electronics

Samsung Unveils New Odyssey Gaming Monitor Lineup

COLORFUL Launches iGame GeForce RTX 50 MINI OC Series Graphics Cards for Compact PCs
GPUs

COLORFUL Launches iGame GeForce RTX 50 MINI OC Series Graphics Cards for Compact PCs

LG Display unveils world’s first 240Hz RGB stripe OLED panel
Enterprise & IT

LG Display unveils world’s first 240Hz RGB stripe OLED panel

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed