Site icon Panda Security Mediacenter

OnMouseOver XSS Vulnerability on Twitter

This morning we observed a Cross Site Scripting (XSS) attack taking place on Twitter.  This particular vulnerability took advantage of the onmouseover function in JavaScript, which works by executing JavaScript code by simply moving your mouse over some text.

The following status updates were observed, causing unsuspecting user feeds to fill up with images of rainbows:

Mouseover Vulnerabilty on Twitter

After hovering over the mouseover code:

Tweet after Mouseover Vulnerability

Here are some of our observations on this attack:

This particular attack could have been nasty in the hands of skilled cyber criminals, but fortunately the Twitter staff have already patched the site against this and future attacks like it.

Twitter Status Update
Exit mobile version