Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Clickjacking Twitter is no tweet

twitter_logo_s.png
From the 'click here, tweet there' files:

Can you Clickjack Twitter? Apparently you can.

This week thanks to, Microsoft's IE 8, a followup story I did about it and a blog post yesterday I had on another clickjacking issue - this is a type of attack that is top of mind for me.  With clickjacking, a user clicks on something that has a hidden element behind it that in turn triggers an unexpected action.

After my post yesterday, I was made aware of some research by James Padolsey clearly showing how a Twitter clickjack can be performed.

Basically what happens is when the user clicks a button an -unintended- message is tweeted. You need to be logged into the Twitter.com web interface for this 'attack' to work. If you're on Firefox, the clickjack is clearly identified by using the NoScript add-on ( click the screen shot below).
clickjacktwitter.jpg

This isn't a flaw in Twitter persay, it's more of a browser issue. That said if you're logged into the web interface of Twitter in one tab and doing other things in another tab well..you could cause a little trouble (but just a little). Might also be a good cause for pause for Twitter user to think about using a Twitter client (I'm currently using Twhirl) which would also mitigate the risk since a web click wouldn't translate over to the client.

There are legitimate reasons why someone would want to click from one page to post to Twitter though (without having to hide it as a clickjack that is). For example if I want you (yes you dear reader) to retweet this page:

TweetThis .

Don't worry in this case if you click the link you still have to click update in the Twitter web interface. Oh and hey if you want to follow me I'm here.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Clickjacking Twitter is no tweet.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/6499

Leave a comment