Home / Series / Tom Scott / Aired Order / Season 2014 / Episode 63

How The Self-Retweeting Tweet Worked: Cross-Site Scripting (XSS) and Twitter

It should never have happened. Defending against cross-site scripting (XSS) attacks is Web Security 101. And yet, today, there was a self-retweeting tweet that hit a heck of a lot of people - anyone using Tweetdeck, Twitter's "professional" client. How did it work? Time to break down the code. (Remember the old Myspace worms? They worked the same way.)

English
  • Originally Aired June 11, 2014
  • Runtime 6 minutes
  • Network YouTube
  • Created July 30, 2023 by
    josh42
  • Modified July 30, 2023 by
    josh42