The onMouseOver incident. It’s not a twisted technology murder mystery. It’s the name Twitter is giving the latest attack on its just-redesigned micro-blogging site.
On Tuesday morning, Twitter was flooded with posts that tapped into a flaw in the site’s programming to dispatch pornography and spread worms to innocent tweeters. The attack was launched against Twitter’s old user interface rather than the new design the company is in the process of rolling out.
Here’s Twitter’s account of the breach: “This morning at 2:54 a.m. PDT Twitter was notified of a security exploit that surfaced about a half hour before that, and we immediately went to work on fixing it. By 7:00 a.m. PDT, the primary issue was solved. And, by 9:15 a.m. PDT, a more minor but related issue tied to hovercards was also fixed.”
An Old Trick
Behind the scenes, the security exploit was created by cross-site scripting, or XSS. Cross-site scripting is the practice of placing code from an untrusted web site into another one. In this case, Twitter explained, users submitted JavaScript code as plain text into a Tweet that could be executed in the browser of another user. Twitter discovered and patched this issue last month. However, a recent site update — one that was unrelated to the new Twitter rollout — unknowingly reopened it.
“Early this morning, a user noticed the security hole and took advantage of it on Twitter.com. First, someone created an account that exploited the issue by turning tweets different colors and causing a pop-up box with text to appear when someone hovered over the link in the Tweet,” Twitter said in its blog. “This is why folks are referring to this an ‘onMouseOver’ flaw — the exploit occurred when someone moused over a link.”
As Twitter explained it, other users took this one step further and…