Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Tweetdeck beats down XSS bug

by The Gurus
June 12, 2014
in Editor's News
Share on FacebookShare on Twitter

Twitter desktop application Tweetdeck had a major cross-site scripting (XSS) bug last night.

While owner Twitter fixed the bug, users were encouraged not to use the application and change passwords as the application spouted random text in place of regular tweets. According to reports, systems were randomly retweeting messages containing potentially malicious scripts.

Mashable reported that a 19-year old Austrian named Firo Xi found the flaw, but denied that it was a deliberate hacking effort. He reported the flaw to Twitter who have declined to comment.

Asked how such a well-deployed application could be affected by such a standard flaw, Tom Cross, director of security research at Lancope, said: “XSS vulnerabilities are fairly common web application bugs that have been well understood by security professionals for a very long time. Any organisation that runs a website should be testing their code for these vulnerabilities before they go into production.
 
“In this case, the consequence of the attack is mostly the ability to create annoying pop-ups that spread virally between users, but in other contexts XSS vulnerabilities can have more serious implications, which is why its important to check for them.”
 
Michael Sutton, VP of security research, Zscaler, said: ”While developers have become more aware of XSS and programing environments and browsers have introduced automated protection mechanisms, XSS remains the most common vulnerability seen in web apps.
 
“It remains a common flaw even on popular internet properties as it can be challenging to properly validate all user supplied input, especially when trying to be flexible and allow users to post rich media content.”
 

Trey Ford, global security strategist at Rapid7, commented that this “attack” was a worm that self-replicates by creating malicious tweets.

“The guidance from Tweetdeck is simple and correct – log out, and log back in. One of the most common and useful XSS attacks is used to steal the user’s session, effectively enabling an attacker to log in as you,” he said.

Asked how websites can protect themselves, Sean Power, security operations manager at DOSarrest, said: “Websites like Tweetdeck can limit the chances of getting malicious code website by routinely auditing the website for unintended inclusions. But with XSS, especially non-persistent XSS, the best thing is to validate all data coming in and make sure what is coming in is sanitised, or checked for malicious code.

“This is especially true for parts of your website that get regular source code updates. It is not enough to just assume that because it was clean before, new updates will also be also be clear.”

ShareTweet
Previous Post

Respect Network Launches a New Paradigm

Next Post

Feedly face DDoS, but refuse to pay attacker's ransom demand

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol