SHARE
Facebook X Pinterest WhatsApp

Clickjacking Twitter is no tweet

Jan 30, 2009
twitter_logo_s.png

From the

click here, tweet there

files:

Can you Clickjack Twitter? Apparently you can.

This week thanks to, Microsoft’s IE 8, a followup story I did about it and a blog post yesterday I had on another clickjacking issue – this is a type of attack that is top of mind for me.  With clickjacking, a user clicks on something that has a hidden element behind it that in turn triggers an unexpected action.

After my post yesterday, I was made aware of some research by James Padolsey clearly showing how a Twitter clickjack can be performed.

Basically what happens is when the user clicks a button an -unintended- message is tweeted. You need to be logged into the Twitter.com web interface for this ‘attack’ to work. If you’re on Firefox, the clickjack is clearly identified by using the NoScript add-on ( click the screen shot below).

clickjacktwitter.jpg

This isn’t a flaw in Twitter persay, it’s more of a browser issue. That said if you’re logged into the web interface of Twitter in one tab and doing other things in another tab well..you could cause a little trouble (but just a little). Might also be a good cause for pause for Twitter user to think about using a Twitter client (I’m currently using Twhirl) which would also mitigate the risk since a web click wouldn’t translate over to the client.

There are legitimate reasons why someone would want to click from one page to post to Twitter though (without having to hide it as a clickjack that is). For example if I want you (yes you dear reader) to retweet this page:


followers.”>TweetThis
.

Don’t worry in this case if you click the link you still have to click update in the Twitter web interface. Oh and hey if you want to follow me I’m here.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.