How The Self-Retweeting Tweet Worked: Cross-Site Scripting (XSS) and Twitter

  • Published on: 11 June 2014
  • - - It should never have happened. Defending against cross-site scripting (XSS) attacks is Web Security 101. And yet, today, there was a self-retweeting tweet that hit a heck of a lot of people - anyone using Tweetdeck, Twitter's "professional" client. How did it work? Time to break down the code. (Remember the old Myspace worms? They worked the same way.)

  • Runtime : 6:17
    Oh my God I love his accent

    You know that if the user icon is a pony, you already lost.

    "find the parents" ...I've been trying

    I feel like this was probably done to point out the glaring flaw, since it's ultimately victimless but will definitely get attention. Either way, interesting to learn!

    I don't understand but somehow still enjoyed the video.You're a wizard Tommy

    i dont use twitter nor do i see a need for it

    Honestly, I learned more about code in this video than most tutorials on here

    <script> i like kids </script>

    [b] bold with what tom said [b/]bold with asterisk

    I think you could have gone into more detail about why this is so important. Your viewers may just shrug off a self-retweeting treat as something kind of benign, and it is. But the tweet could have done so much more, like stealing login sessions of the user. This reason this is a big deal is because it exposes an XSS vulnerability, not that someone's tweet can retweet

    How the hell do these people know so much random stuff

    One time I commented on YouTube and it become script. I don't know how

    “Im oversimplifying here”“never ever EVER”“Well done (insert name here)”

    do you mean The Future

    also can someone please upload videos made from old cameras :(

    I tried to reply but then met the word ironically. But it was BISMUTH AND SOME STUPID APP AND EBAY