Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Worms

Twitter Gets Slammed By the StalkDaily XSS Worm 145

CurtMonash writes "Twitter was hit Saturday by a worm that caused victims' accounts to tweet favorably about the StalkDaily website. Infection occurred when one went to the profile page of a compromised account, and was largely spread by the kind of follower spam more commonly used by multi-level marketers. Apparently the worm was an XSS attack, exploiting a vulnerability created in a recent Twitter update that introduced support for OAuth, and it was created by the 17-year-old owner of the StalkDaily website. More information can be found in the comment thread to a Network World post I put up detailing the attack, or in the post itself. By evening, Twitter claimed to have closed the security hole."

Comment Re:Real Identity? (Score 1) 740

Highly dependent on your setup. Your scenario is similar to setting up procmail to gpg sign and return anything you send me. While it is possible, it would be stupid to configure a system as such.

Slashdot Top Deals

All I ask is a chance to prove that money can't make me happy.

Working...