Today one of our favorite sites, TwitterTwitter reviews, was hit with a particularly nasty exploit: one that could infect users simply by visiting a friend’s profile on Twitter.com. (At the time of writing, the exploit is still at large.)
The nature of the attack was far more serious than previous exploits, since there was no need to click a link to get infected. In fact, there’s an element of deja-vu in this exploit, since it’s much the same one used to target MySpaceMySpace reviews in its heyday: a cross site scripting (XSS) attack.
What Happened: Our Best Guess
While reports are still coming in and we’re trying to keep this lightweight enough for everyone to understand, here’s our draft summary of the steps taken by the attacker (please add info and explanations in the comments section and we’ll continue to update this). The attacker:
1. Realized that Twitter allows you to insert not just a URL in your “bio” section, but also a script (a quick glance at the source suggests that the javascript used is hidden in the color attribute and hosted at a site calle