• bitcoinBitcoin (BTC) $ 61,225.00
  • ethereumEthereum (ETH) $ 2,932.19
  • tetherTether (USDT) $ 0.999871
  • bnbBNB (BNB) $ 592.26
  • solanaSolana (SOL) $ 145.42
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.505778
  • staked-etherLido Staked Ether (STETH) $ 2,929.99
  • the-open-networkToncoin (TON) $ 6.96
  • dogecoinDogecoin (DOGE) $ 0.143470
  • cardanoCardano (ADA) $ 0.440985
  • shiba-inuShiba Inu (SHIB) $ 0.000023
  • avalanche-2Avalanche (AVAX) $ 33.78
  • tronTRON (TRX) $ 0.126549
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,218.00
  • polkadotPolkadot (DOT) $ 6.73
  • bitcoin-cashBitcoin Cash (BCH) $ 437.37
  • chainlinkChainlink (LINK) $ 13.46
  • nearNEAR Protocol (NEAR) $ 7.02
  • matic-networkPolygon (MATIC) $ 0.679682
  • litecoinLitecoin (LTC) $ 81.63
  • fetch-aiFetch.ai (FET) $ 2.21
  • internet-computerInternet Computer (ICP) $ 11.92
  • daiDai (DAI) $ 0.999413
  • leo-tokenLEO Token (LEO) $ 5.89
  • uniswapUniswap (UNI) $ 7.12
  • render-tokenRender (RNDR) $ 11.05
  • hedera-hashgraphHedera (HBAR) $ 0.110888
  • ethereum-classicEthereum Classic (ETC) $ 26.67
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • pepePepe (PEPE) $ 0.000009
  • aptosAptos (APT) $ 8.43
  • cosmosCosmos Hub (ATOM) $ 8.60
  • crypto-com-chainCronos (CRO) $ 0.124860
  • mantleMantle (MNT) $ 1.02
  • immutable-xImmutable (IMX) $ 2.27
  • wrapped-eethWrapped eETH (WEETH) $ 3,040.12
  • filecoinFilecoin (FIL) $ 5.65
  • stellarStellar (XLM) $ 0.105827
  • dogwifcoindogwifhat (WIF) $ 3.01
  • okbOKB (OKB) $ 49.73
  • blockstackStacks (STX) $ 2.00
  • kaspaKaspa (KAS) $ 0.122905
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,884.77
  • arweaveArweave (AR) $ 42.14
  • the-graphThe Graph (GRT) $ 0.287212
  • optimismOptimism (OP) $ 2.57
  • arbitrumArbitrum (ARB) $ 1.01
  • bittensorBittensor (TAO) $ 377.00
  • vechainVeChain (VET) $ 0.034760
  • makerMaker (MKR) $ 2,692.24
  • moneroMonero (XMR) $ 133.50
  • suiSui (SUI) $ 1.01
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • injective-protocolInjective (INJ) $ 24.06
  • thorchainTHORChain (RUNE) $ 6.11
  • fantomFantom (FTM) $ 0.728054
  • theta-tokenTheta Network (THETA) $ 2.00
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,237.60
  • celestiaCelestia (TIA) $ 9.12
  • flokiFLOKI (FLOKI) $ 0.000171
  • lido-daoLido DAO (LDO) $ 1.78
  • bitget-tokenBitget Token (BGB) $ 1.09
  • bonkBonk (BONK) $ 0.000023
  • galaGALA (GALA) $ 0.042593
  • coredaoorgCore (CORE) $ 1.70
  • algorandAlgorand (ALGO) $ 0.180317
  • jupiter-exchange-solanaJupiter (JUP) $ 1.07
  • whitebitWhiteBIT Coin (WBT) $ 9.89
  • sei-networkSei (SEI) $ 0.504521
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,016.36
  • quant-networkQuant (QNT) $ 95.21
  • akash-networkAkash Network (AKT) $ 5.52
  • flowFlow (FLOW) $ 0.848894
  • worldcoin-wldWorldcoin (WLD) $ 5.89
  • aaveAave (AAVE) $ 83.43
  • bitcoin-svBitcoin SV (BSV) $ 62.24
  • ethenaEthena (ENA) $ 0.849573
  • singularitynetSingularityNET (AGIX) $ 0.928647
  • beam-2Beam (BEAM) $ 0.023701
  • ondo-financeOndo (ONDO) $ 0.792551
  • bittorrentBitTorrent (BTT) $ 0.000001
  • flare-networksFlare (FLR) $ 0.028083
  • dydx-chaindYdX (DYDX) $ 2.03
  • chilizChiliz (CHZ) $ 0.125516
  • ribbon-financeRibbon Finance (RBN) $ 1.15
  • neoNEO (NEO) $ 15.48
  • wormholeWormhole (W) $ 0.602467
  • elrond-erd-2MultiversX (EGLD) $ 39.36
  • cheeleeCheelee (CHEEL) $ 18.58
  • gatechain-tokenGate (GT) $ 8.09
  • zebec-protocolZebec Protocol (ZBC) $ 0.020147
  • axie-infinityAxie Infinity (AXS) $ 7.04
  • kucoin-sharesKuCoin (KCS) $ 10.33
  • pendlePendle (PENDLE) $ 4.34
  • the-sandboxThe Sandbox (SAND) $ 0.424307
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.53
  • ecasheCash (XEC) $ 0.000046
  • eosEOS (EOS) $ 0.787111
  • msolMarinade Staked SOL (MSOL) $ 173.18
  • tezosTezos (XTZ) $ 0.903383
  • starknetStarknet (STRK) $ 1.22
  • mina-protocolMina Protocol (MINA) $ 0.802649
  • jasmycoinJasmyCoin (JASMY) $ 0.018049
  • aioz-networkAIOZ Network (AIOZ) $ 0.797163
  • conflux-tokenConflux (CFX) $ 0.210809
  • roninRonin (RON) $ 2.62
  • havvenSynthetix Network (SNX) $ 2.57
  • heliumHelium (HNT) $ 4.96
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,944.17
  • decentralandDecentraland (MANA) $ 0.416607
  • ordinalsORDI (ORDI) $ 36.54
  • apecoinApeCoin (APE) $ 1.22
  • safeSafe (SAFE) $ 1.79
  • book-of-memeBOOK OF MEME (BOME) $ 0.010864
  • gnosisGnosis (GNO) $ 286.46
  • usddUSDD (USDD) $ 0.996602
  • dexeDeXe (DEXE) $ 12.79
  • nervos-networkNervos Network (CKB) $ 0.016063
  • kavaKava (KAVA) $ 0.643324
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.60
  • nexoNEXO (NEXO) $ 1.23
  • pyth-networkPyth Network (PYTH) $ 0.459804
  • iotaIOTA (IOTA) $ 0.210774
  • axelarAxelar (AXL) $ 1.04
  • lido-staked-solLido Staked SOL (STSOL) $ 172.50
  • theta-fuelTheta Fuel (TFUEL) $ 0.100555
  • fraxFrax (FRAX) $ 0.999082
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,926.25
  • fasttokenFasttoken (FTN) $ 1.95
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000104
  • klay-tokenKlaytn (KLAY) $ 0.166384
  • ocean-protocolOcean Protocol (OCEAN) $ 0.932230
  • echelon-primeEchelon Prime (PRIME) $ 15.32
  • frax-etherFrax Ether (FRXETH) $ 2,914.42
  • bitcoin-goldBitcoin Gold (BTG) $ 33.94
  • blurBlur (BLUR) $ 0.370693
  • tether-goldTether Gold (XAUT) $ 2,364.58
  • oasis-networkOasis Network (ROSE) $ 0.086029
  • swethSwell Ethereum (SWETH) $ 3,087.05
  • livepeerLivepeer (LPT) $ 17.82
  • mantra-daoMANTRA (OM) $ 0.697220
  • arkhamArkham (ARKM) $ 2.56
  • wemix-tokenWEMIX (WEMIX) $ 1.55
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000026
  • osmosisOsmosis (OSMO) $ 0.830993
  • dydxdYdX (ETHDYDX) $ 2.03
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,132.91
  • illuviumIlluvium (ILV) $ 84.42
  • golemGolem (GLM) $ 0.535200
  • curve-dao-tokenCurve DAO (CRV) $ 0.427216
  • woo-networkWOO (WOO) $ 0.276209
  • xdce-crowd-saleXDC Network (XDC) $ 0.036826
  • true-usdTrueUSD (TUSD) $ 0.999627
  • astarAstar (ASTR) $ 0.089982
  • dymensionDymension (DYM) $ 2.94
  • jito-governance-tokenJito (JTO) $ 4.08
  • apenftAPENFT (NFT) $ 0.00000049
  • iotexIoTeX (IOTX) $ 0.050401
  • mx-tokenMX (MX) $ 4.81
  • venomVenom (VENOM) $ 0.287107
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,167.63
  • radixRadix (XRD) $ 0.044477
  • superfarmSuperVerse (SUPER) $ 1.01
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.08
  • altlayerAltLayer (ALT) $ 0.325885
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.03
  • ankrAnkr Network (ANKR) $ 0.043578
  • pax-goldPAX Gold (PAXG) $ 2,340.84
  • raydiumRaydium (RAY) $ 1.64
  • stepnGMT (GMT) $ 0.212476
  • corgiaiCorgiAI (CORGIAI) $ 0.001234
  • popcatPopcat (POPCAT) $ 0.437430
  • zilliqaZilliqa (ZIL) $ 0.023043
  • 1inch1inch (1INCH) $ 0.364598
  • celoCelo (CELO) $ 0.784811
  • memecoin-2Memecoin (MEME) $ 0.024187
  • ether-fiEther.fi (ETHFI) $ 3.63
  • manta-networkManta Network (MANTA) $ 1.66
  • enjincoinEnjin Coin (ENJ) $ 0.286069
  • polymeshPolymesh (POLYX) $ 0.396303
  • aerodrome-financeAerodrome Finance (AERO) $ 0.929084
  • terra-luna-2Terra (LUNA) $ 0.595861
  • amp-tokenAmp (AMP) $ 0.007253
  • rocket-poolRocket Pool (RPL) $ 19.89
  • zetachainZetaChain (ZETA) $ 1.68
  • holotokenHolo (HOT) $ 0.002221
  • siacoinSiacoin (SC) $ 0.006830
  • project-galaxyGalxe (GAL) $ 3.38
  • ravencoinRavencoin (RVN) $ 0.028235
  • 0x0x Protocol (ZRX) $ 0.457635
  • aelfaelf (ELF) $ 0.531108
  • paypal-usdPayPal USD (PYUSD) $ 0.998935
  • safepalSafePal (SFP) $ 0.803893
  • compound-governance-tokenCompound (COMP) $ 54.23
  • qtumQtum (QTUM) $ 3.52
  • skaleSKALE (SKL) $ 0.071494
  • stader-ethxStader ETHx (ETHX) $ 3,005.31
  • nosanaNosana (NOS) $ 4.35
  • compound-wrapped-btccWBTC (CWBTC) $ 1,227.13

Twitter User Finds Critical Bug That Could Have Wrecked Your X Account—And Gets Banned for It

0 68

Twitter User Finds Critical Bug That Could Have Wrecked Your X Account—And Gets Banned for It

  decrypt.co 2 h

Twitter User Finds Critical Bug That Could Have Wrecked Your X Account—And Gets Banned for It

For more than a year, all it would take is clicking on a maliciously crafted link on Twitter and your account could have been taken over and used to tweet, retweet, like, or block other users. The vulnerability was disclosed publicly on Wednesday, leading to a quick fix—and a scolding for the user who disclosed it.

Instead of earning a monetary reward from Twitter’s bug bounty program, the company banned the user from participating.

I submitted this bug report and didn’t receive a bounty. You told me that this bug has existed for a year. Seeing that you haven’t fixed it for so long, it seems that this bug is not important, so I made it public. pic.twitter.com/R9X4k8KqMZ

— rabbit (@rabbit_2333) December 12, 2023

The disclosure was made by pseudonymous Twitter user @rabbit_2333, who shared how an XSS vulnerability on Twitter’s analytics subdomain could be leveraged to give an attacker access to a third party’s profile and the ability to do almost everything except changing the account’s password.

The hack made use of cross-site scripting (XSS) and cross-site request forgery (CSRF). XSS attacks allow malicious actors to inject harmful scripts into web pages, while CSRF tricks users into executing actions on a web app where they’re already authenticated.

The Twitter bug ytilized both these methods, making it especially dangerous. By exploiting XSS, attackers could bypass web security measures and gain unauthorized access to user accounts.

As news of this vulnerability spread, Chaofan Shou, cofounder of the smart contract analysis platform Fuzz.Lan, stepped in to provide more details. He revealed how easy it was to build a powerful exploit tool based on this unaddressed vulnerability, and proovided a detailed explanation of how the bug worked and the potential damages it could cause.

😝 Here is the full disclosure of the Twitter XSS + CSRF vulnerability.

Clicking a crafted link or going to some crafted web pages would allow attackers to take over your account (posting, liking, updating your profile, deleting your account, etc.) pic.twitter.com/MVJ1MvHt6H

— Chaofan Shou (@shoucccc) December 13, 2023

Shou’s write up was followed by comments from cybersecurity researcher Sam Sun, who provided practical advice on how to avoid the exploit, and highlighting the lack of safety even for those using Twitter on their phones via browsers.

If you’re using Twitter on your phone in your browser, you’re vulnerable because you can’t install extensions, so just log out and use the app instead (or if you’re an app purist, just live without Twitter for a few days)

— samczsun (@samczsun) December 13, 2023

Sun noted that the privacy-centric web browser Brave would have prevented the exploit from working.

Twitter’s response was swift following this public disclosure. Within hours, they had patched the vulnerability, as confirmed by Sun. Despite the potential severity of the flaw, however, @rabbit_2333 was not rewarded for his discovery. Instead, he was notified of his banishment from Twitter’s bug bounty program.

“Thank you Twitter,” the user wrote, with screenshots of Twitter’s ban notification.

As comments flooded in about whether @rabbit_2333 should have posted about the bug or not, the user claimed that they did follow proper protocol at first. It was only when Twitter dismissed the severity and its eligibility for a bounty that they went public, the user said.

I submitted this bug report and didn’t receive a bounty. You told me that this bug has existed for a year. Seeing that you haven’t fixed it for so long, it seems that this bug is not important, so I made it public. pic.twitter.com/R9X4k8KqMZ

— rabbit (@rabbit_2333) December 12, 2023

The purpose of bug bounty programs is to prevent incidents like this one, incentivising developers to discover security holes with rewards and an agreement not to disclose them while the company fixes things.

Bug bounty programs are common in software development, as well as in cryptocurrency, particularly when dealing with smart contracts. While running such programs can be challenging, the prevention of a security breach is typically seen as worth the effort.

White-hat and bug-bounty incentive programs typically require vulnerabilities to be kept confidential. But they also often have expiration dates, to ensure the software developer acts in a timely manner.

Edited by Ryan Ozawa.

Source

Leave A Reply

Your email address will not be published.