Web Hack List

Collected research

TweetDeck XSS

TweetDeck Taken Down in Wake of XSS Attacks

TweetDeck rendered tweet content as live markup, so a script tag inside a tweet executed in every reader's client. The published payload used the client's own retweet control to repost itself, producing a self-spreading worm that also allowed account takeover, and Twitter pulled the service to patch it.

Record

Document
TweetDeck Taken Down in Wake of XSS Attacks
Researcher
Michael Mimoso
Published by
Threatpost - English - Global - threatpost.com
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Mimoso, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .