Live data from Hacker News

XSS in Tweetdeck (don't view in Tweetdeck...)

twitter.com

11–20 of 26 posts

Re: XSS in Tweetdeck (don't view in Tweetdeck...)

#12
post #8

What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....

Has to do with the emoji support, I'm pretty sure.

Re: XSS in Tweetdeck (don't view in Tweetdeck...)

#13
I guess the New York Times uses Tweetdeck[1]. I saw this because several people I follow had retweeted it and the Twitter app notifies you if several of your followers do the same thing. It's a useful feature. If Tweetdeck does the same thing it could make this spread really fast.

[1] https://twitter.com/derGeruhn/status/476764918763749376

Re: XSS in Tweetdeck (don't view in Tweetdeck...)

#14
post #9

So apparently this was retweeted by @5SOS, a teen pop band with some 3 million followers, which is why most of the responses are confused teenagers. For some reason this is hilarious to me. Not the pinnacle of responsible disclosure, but no real harm done.

Obviously their social media agent uses tweetdeck...

Re: XSS in Tweetdeck (don't view in Tweetdeck...)

#16
post #8

What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....

Apparently it was only activated if you included an emoticon (<3) in your tweet, possibly following the closing script tag.

Re: XSS in Tweetdeck (don't view in Tweetdeck...)

#20
post #8

What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....

Apparently it was only activated if you included an emoticon (<3) in your tweet, possibly following the closing script tag.

Any UTF8 char actually 💩
Post reply on HN