XSS in Tweetdeck (don't view in Tweetdeck...)
11–20 of 26 posts
Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#12What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....
Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#13Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#14So apparently this was retweeted by @5SOS, a teen pop band with some 3 million followers, which is why most of the responses are confused teenagers. For some reason this is hilarious to me. Not the pinnacle of responsible disclosure, but no real harm done.
Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#15Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#16What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....
Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#17[1] http://www.theguardian.com/technology/2014/jun/11/twitter-tw...
Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#18Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#19Re: XSS in Tweetdeck (don't view in Tweetdeck...)
#20What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. javascript is the first payload you try when looking for the stupidest XSS you can find....
Apparently it was only activated if you included an emoticon (<3) in your tweet, possibly following the closing script tag.