I just wrote a proof-of-concept worm that steals session cookies. It spreads by retweeting. If something like this was released it would spread like wildfire. Reminds me of the MySpace worm that took the site down Time to change your passwords! (Edit: I will post the vuln code once this is patched. Atm I am playing with having the payload make Ajax queries back to Twitter :). Having shortcut functions in the page (ie…
Is this a twitter-only problem with the way the URLs are formed? Or is this a common way of injecting JS into links on other sites as well?
So this attack won't work on other sites that escape URLs properly.