<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DVV Blog &#187; hack</title>
	<atom:link href="http://davidvanvickle.com/blog/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://davidvanvickle.com/blog</link>
	<description>Work that web.</description>
	<lastBuildDate>Mon, 12 Jul 2010 00:02:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Awakened by Mikeyy. Little punk.</title>
		<link>http://davidvanvickle.com/blog/2009/04/12/awakened-by-mikeyy/</link>
		<comments>http://davidvanvickle.com/blog/2009/04/12/awakened-by-mikeyy/#comments</comments>
		<pubDate>Sun, 12 Apr 2009 21:18:42 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[javascript]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[crosssitescriptingattack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://davidvanvickle.com/blog/?p=336</guid>
		<description><![CDATA[I was browsing Twitter late into the night.  At some point I hit a profile with a funny ASCII animation at the top.  Maybe that was where it started, I don&#8217;t know. This is what I saw in my Twitter account&#8230; Dude! Mikeyy! Seriously? Haha. Dude, Mikeyy is the shit! Dude, Mikeyy is the shit! ]]></description>
			<content:encoded><![CDATA[<p>I was browsing Twitter late into the night.  At some point I hit a profile with a funny ASCII animation at the top.  Maybe that was where it started, I don&#8217;t know.</p>
<p>This is what I saw in my Twitter account&#8230;</p>
<p>Dude! Mikeyy! Seriously? Haha. <img src='http://davidvanvickle.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
Dude, Mikeyy is the shit! <img src='http://davidvanvickle.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Dude, Mikeyy is the shit! <img src='http://davidvanvickle.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>What I do know is I woke up and was unpleasantly surprised.  I checked my emails.  A nice and informed person had notified me that my Twitter profile had been hit with the &#8220;mikeyy exploit&#8221; and I may want to check it out and change my password or something.</p>
<p>He left me this link to read up on the situation.</p>
<p><a href="http://www.sophos.com/blogs/gc/">http://www.sophos.com/blogs/gc/</a></p>
<p>Then I went to search.twitter.com and looked up tweets people had sent me.  Other people were either asking why I was saying things about Mikeyy, but some knew what was happening and sent more links like this one.</p>
<p><a href="http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/">http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/</a></p>
<p>I don&#8217;t claim to understand what exactly happened, other than it seems some temporary Javascript can be applied to a page and funny business can be made to happen on that page by a page from another site.  This is apparently called a cross-site scripting attack or XSS.</p>
<p><a href="http://en.wikipedia.org/wiki/Cross-site_scripting">http://en.wikipedia.org/wiki/Cross-site_scripting</a></p>
<p>The issue can be addressed by Firefox users with the &#8220;NoScript&#8221; extension.  I hate the idea of installing this.  Seems like there should be a better way.  Indeed maybe one of Explorer&#8217;s annoying popups has addressed it over in that camp.  I need to look more into that.</p>
<p>Here is the Firefox solution.</p>
<p><a href="http://noscript.net/">http://noscript.net/</a></p>
<p>I have installed it.  It is annoying.  I went into the preferences and cranked it down a little.  There is also an &#8220;S&#8221; logo at the bottom of the browser that lets me change specific preferences for a site.  I turned on a sound effect when it is called up so I can change the settings for a given site and not miss the intended and good functionality of that site.</p>
<p>In this particular situation, I do not believe the code is still in my Twitter profile.  I think last night&#8217;s issue has been resolved.</p>
<p>Being someone who makes websites and loves Javascript, this is a troubling fix.  The browsers should step it up here, as they may have already begun doing.</p>
<p>I have exposed some of my ignorance here.  I hope if you know more you will leave a helpful comment below.  Thank you!</p>
]]></content:encoded>
			<wfw:commentRss>http://davidvanvickle.com/blog/2009/04/12/awakened-by-mikeyy/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>
