Twitter 'onmouseover' security flaw hits site

Sarah Brown - victim of a Twitter hack
Sarah Brown - victim of a Twitter hack

UPDATE: Twitter has announced it has fixed the security flaw, explaining on its Twitter Status blog: "The exploit is fully patched."

Twitter is blaming the hack on an XSS (cross-site scripting) attack.

ORIGINAL STORY

A security flaw has appeared on micro-blogging site Twitter, which allows third-party sites to open up in your browser when you simply hover your mouse pointer over a link.

The hack has targeted thousands of profiles and even redirected readers of Sarah Brown's Twitter feed to a Japanese porn site.

Mouse in the house

Security firm Sophos has outlined the potential problems with the flaw, which uses a piece of Javascript code – called onMouseOver – that allows you to be redirected to another site without even clicking on a link.

Although Sophos believes that the flaw is "innocuous" at the moment, it is recommending all users to use a third-party client to access Twitter and not go directly to the main site until the Javascript code has been blocked.

If you are using the site, then it is recommended you don't click any link with the 'onmouseover' command, or ones which contain blocks of colour (rainbow tweets) as these can hide their true content.

Go to www.sophos.com/blogs for more details.

If you are stuck on which third-party app to use, don't worry as TechRadar has compiled two lists: six of the best Twitter web apps and the 12 best Twitter apps to help you make a decision.

Here SophosLabs has created a video to explain the situation:

Marc Chacksfield

Marc Chacksfield is the Editor In Chief, Shortlist.com at DC Thomson. He started out life as a movie writer for numerous (now defunct) magazines and soon found himself online - editing a gaggle of gadget sites, including TechRadar, Digital Camera World and Tom's Guide UK. At Shortlist you'll find him mostly writing about movies and tech, so no change there then.

Latest in Mice
Two examples of the Asus Fragrance Mouse MD101 sitting on a table
Your next computer mouse could have a fragrance compartment for aromatherapy oils – and this Asus idea is nothing to sniff at
The Asus ROG Harpe Ace Mini gaming mouse on a table
The Asus ROG Harpe Ace Mini might be small, but few mice have impressed me this much
Logitech POP on plinth with pink and plant in background
I love the feel of the Logitech POP Mouse, but it does miss out on a few features
Cherry XTRFY M64 Wireless on table with pink background and plant
The Cherry XTRFY M64 Wireless fits my hand like a glove, but I'm not sure it's the best value gaming mouse around
The Razer Basilisk V3 Pro 35K gaming mouse against a blue background.
Razer Basilisk V3 Pro 35K: Everyday excellence
MSI Clutch GM41 Lightweight V2 on desk
MSI Clutch GM41 Lightweight V2 review: a basic, lightweight gaming mouse that doesn’t quite live up to its potential
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras