
Twitter: no-follow on all links, security problem untouched Last week Twitter closed a 'loophole' for SEOs to get free no-follow links to their website. Twitter added rel=nofollow to links produced by their API. That meant links in lines like "1 minute ago from TweetDeck" were no longer followed to the application, in this case Tweetdeck. Dave showed us he could have easily gained access to any Twitter-users login cookie and therefore making hacking really easy. Dave gave us an example using a especcially set up account which got suspended the same day. You can see the example in this video Dave made: The 'failure' in Twitter could easily be fixed by Twitter developers, but a day later they hadn't. That makes Twitter very vulnerable for hackers. Within minutes anyone with a little technical knowledge could be sending out tweets tricking followers in clicking on the links and taking over their accounts. ![]() The opening Dave exposed is something we shouldn't underestimate. The taking over of accounts can be used for all sorts of malicious things. It is for example not unexpected if many use the same password for their Twitter account as for their GMail, hotmail or any other service. In his second post Dave goes into more of the technical details. These are quite stunning. Whatever you type in the application box will appear on the end of tweets, and you can past html or even javascript. ![]() Dave pointed at some ways to prevent you from getting your account being hacked:
Chances are that if you use a third party Twitter client you'll be allright, but be sure to use any of the popular ones. Using the Twitter website could be dangerous however. Be sure to read both Dave's posts on this on his blog to get the full story and how to. This move is a blow for linkbuilders who can no longer rely directly on Twitter, but even more important: Twitter seems to be closing the walls around them. It looks a lot like how Wikipedia works: internal links do matter, external links won't. How will SEO's handle this one? Dave, any suggestions? ;) CommentRelated tweets
|
Last Comments
Bloggers
Latest Videos![]() SEO Roadshow: interview wit... More than a month ago the SEO-Chicks weblog started a contest to find new recruits for their b... Columns
Tagcloudnews twitter search engine google analytics bing website search google maps google wave funny london sea images privacy business social media spain sem advertising searchcowboys yahoo social video a4uexpo street view blogger interview linkbuilding smx seo youtube streetview mobile tools maps adwords gmail research europeMost Commented
AgendaMost Read
|
Search
My BlogLogPodcasts
Blogroll |
© 2010 Searchcowboys.com - All Rights Reserved - All views and opinions expressed are those of the authors of Searchcowboys.
All trademarks, slogans, text or logo representation used or referred to in this website are the property of their respective owners. Sitemap
Comments (5)
Althought this was a serious issue... The 'outing' of the problem by Naylor is just link bait whoring at it's finest.
TechCrunk was guilty of it last month or so...
Do 27 aug 2009, 16:30
William, if that is so, it's a bit strange that TechCrunch wrote a big article about it yesterday giving Dave all te credits?
Could you provide a link to back up what you're saying?
Do 27 aug 2009, 17:12
This was originally a nice little secret and a neat way of getting nofollow links from the Twitter domain.
Then some big mouth blabbed and Twitter fixed the issue. If Twitter had not bothered to fix the nofollow link and let it ride - most people (inlcuding Naylor) would not have been so quick to expose this access point.
As for TechCrunk, they write about anything... Yesterday they reported on a web site that added a 'Share This' bar to their web site... Please.
Do 27 aug 2009, 17:32
Ah William, you must be talking about the no-follow link in the area below the tweet, a loophole which was closed a week ago... http://www.searchcowboys.com/seo/898
This is a different issue resulting from that.
Do 27 aug 2009, 17:44
@tucker where you the one dropping cookies out of twitter with that exploit then ? not many new about that XSS seem you did?
Do 27 aug 2009, 17:47