Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Twitter has fixed a cross-site scripting (XSS) vulnerability that stole a user's cookie to distribute compromised links.It was detected by Stefan Tanase, senior security researcher at Kaspersky Lab. He said that the exploit steals the cookie of the Twitter user, which is transferred to two specific servers, and essentially any account that clicked on the malicious links is compromised.He said that the bit.ly statistics for one of the malicious links show that more than 100,000 users clicked on the link.“All clues point to Brazil as the originating country for this attack. First, the two domain names used to get the stolen cookies are registered under Brazilian names. More than that, one of them is actually also hosted in Brazil,” he said.One of the links was a short tweet in Portuguese about the Brazilian pop band Restart, reportedly suffering a 'tragic accident'. Tanase said there is not much doubt about the origins of this attack.The malicious scripts were detected by Kaspersky Lab as Exploit.JS.Twetti.a, and it has blacklisted the URLs used in this attack.Tanase said: “We are currently working on taking down the malicious URLs and minimising the damage as much as possible. Twitter along with other significant industry peers has of course been notified.”Twitter commented that the vulnerability is now fixed.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.