Another Day, Another Twitter Exploit
Apologies to anyone out there who’s not a Twitter fan (e.g. our very own Carps springs to mind), but this is another Twitter exploit post. If you do use Twitter you’ll likely already have seen this one in action today, and if you don’t, you won’t be interested. Oh well.
The Problem
The actual exploit as I first saw it is quite simple. All it’s based on is sending out a tweet starting with http://t.co/@ and continuing with whatever HTML you want to inject into the page. t.co is Twitter’s homegrown URL shortener, and I would guess that something in their escaping logic is trusting it more than it should. Certainly the http://a.bc/@ I tried didn’t work.




