Email or username:

Password:

Forgot your password?
Adam Shostack :donor: :rebelverified:

"A security researcher uncovered a Twitter vulnerability in its link shortener. The vulnerability allowed an attacker to craft a malicious URL that, if a user clicked on it, would grant the attacker access to the user's account. The researcher reported the vulnerability to Twitter's bug bounty program, which closed the report as not worthy of a bug bounty. So the researcher published the vulnerability. Immediately Twitter takes its link shortener offline for hours while they fix it.But the press is only reporting on an hours-long X/Twitter link shortener outage, and has completely missed the security issues that led to it.Molly White's coverage of the vulnerability (sorry for the Xitter link but that's just the problem, literally no one else is covering this): twitter.com/molly0xFFF/status/ "

Disclosure: x.com/shoucccc/status/17348021

(All quoting a friend on a private slack)

9 comments
RealGene ☣️

@adamshostack
Reposting the content here so you don't have to get tainted:

Molly White @molly0xFFF

twitter not paying whitehats. what could go wrong?

this one just disclosed a vulnerability that would have allowed people to gain control of the twitter accounts of users who merely clicked malicious links

Imran Nazar

@RealGene @adamshostack

Don't suppose you can drag that post over to your Mastodon, @molly0xfff ? I was surprised to find it wasn't already crossposted here.

Molly White

@Two9A i could, i mostly avoid posting about twitter stuff on mastodon because i get the impression people here are pretty sick of hearing about The Bad Place

Champagne

@molly0xfff
Also, those people could just filter Twitter and never see it. I don't understand the users that complain rather than using the tools afforded them!

@Two9A

Go Up