A potentially critical cross-site scripting vulnerability in Twitter has still not been fixed, according to the researcher who discovered the problem.
Search marketing professional James Slater claimed that the vulnerability in the popular micro-blogging site could allow hackers to insert malicious JavaScript into tweets.
"With a few minutes' work, someone with a bit of technical expertise could make a Twitter 'application' and start sending tweets with it," he wrote in a blog post.
"Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter - their account could be taken over."
Despite Twitter promising to fix the problem after being notified by Naylor on Tuesday, the firm's IT team has "completely missed the point", he wrote.
"This isn't the first time we've found vulnerabilities in Twitter. I wonder how many more there are out there?" he added.
"We got no response from them yesterday either, which is a shame. We don't want to stop using their service because we're worried about security, and I'm sure we're not the only ones."
Twitter has yet to officially respond to the news, although many of the comments left on Naylor's blog posting point to the flaw being a "rookie error".
Twitter cross-site scripting flaw 'still not fixed'
By
Phil Muncaster
on Aug 28, 2009 9:20AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Channel can help lead customers to boosting workplace wellbeing with professional headsets

Tech For Good program gives purpose and strong business outcomes

Build cybersecurity capability with award winning Fortinet training from Ingram Micro
Ingram Micro Ushers in the Age of Ultra
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report