海角大神

TweetDeck temporarily brought down by XSS hack

TweetDeck, a popular organization application for Twitter users, was taken offline Wednesday after hackers hit the service with rapid retweets and strange error messages.

|
TweetDeck
TweetDeck was taken offline on Wednesday after hackers launched an XSS attack. TweetDeck was bought by Twitter for $40 million in 2011.

Popular Twitter organization app TweetDeck was taken offline Wednesday after a hack left users dealing with some confusing messages.

TweetDeck users reported a bug that was retweeting code from fake users. That code then spread the retweeting bug to other users. Other TweetDeck users found strange pop-ups containing messages such as 鈥淵o!鈥 and 鈥淧lease close now TweetDeck鈥 it is not safe." Major Twitter accounts were affected by the hack, such as BBC Breaking News. One retweet managed to spread 38,000 times in two minutes.

"TweetDeck appears to have jumped on this issue and patched it, but we're still seeing it spread like wildfire through Twitter," says Trey Ford, a security expert at Rapid7,

"This vulnerability very specifically renders a tweet as code in the browser, allowing various cross site scripting (XSS) attacks to be run by simply viewing a tweet. The current attack we're seeing is a "worm" that self-replicates by creating malicious tweets," he adds.

Initially, TweetDeck thought it had patched the security flaw this morning, and asked users to log out and back in to activate the fix. However, as the pop up messages and retweets continued, TweetDeck eventually shut down.

"We've temporarily taken TweetDeck services down to assess today's earlier security issue,鈥 the company tweeted. 鈥淲e'll update when services are back up."

As of 2:00 pm Eastern, the application was still down, but it seemed to be back up shortly afterward.

TweetDeck is a third-party Twitter platform most frequently used by media organizations and social media professionals. The application allows users to monitor Twitter and post from several different accounts at a time.

TweetDeck was founded in 2008 and was one of the first third-party applications on Twitter to find widespread popularity. Twitter bought TweetDeck, originally a British company, in 2011 for $40 million. Twitter has not yet commented on the hack.

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
What is the Monitor difference? Tackling the tough headlines 鈥 with humanity. Listening to sources 鈥 with respect. Seeing the story that others are missing by reporting what so often gets overlooked: the values that connect us. That鈥檚 Monitor reporting 鈥 news that changes how you see the world.
QR Code to TweetDeck temporarily brought down by XSS hack
Read this article in
/Technology/Horizons/2014/0611/TweetDeck-temporarily-brought-down-by-XSS-hack
QR Code to Subscription page
Start your subscription today
/subscribe