Tuesday, September 21, 2010

Serious Twitter OnMouseOver Exploit

If you're a Twitter user, please stay away from Twitter's website today.

There's a serious javascript vulnerability spreading like wildfire, that makes your browser execute potentially malicious javascript code as soon as you mouse over any link.

Please resist the urge to go see it for yourself - I know I didn't, and as soon as I went there to see what was happening, my browser started opening new windows and "viral" tweets were sent "by me".

Until this issue is cleared by twitter, you can either use a 3rd party Twitter App, or simply disable javascript in your browser.

If you need to logout of your current session, then just head to twitter.com/logout and click the button.

