Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Twitter: Twitter Source Label allow 'mongolian vowel separator' U+180E (app name)

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Twitter: Twitter Source Label allow 'mongolian vowel separator' U+180E (app name)


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Summary: Twitter app-names (which are shown in the Tweet source label) are supposed to be unique and because of that they must not include invisible unicode characters. However, you can use the mongolian vowel separator in these app-name, which allows to fake a app-name. Description: Every tweet has a ['Tweet source label'] (https://help.twitter.com/en/using-twitter/how-to-tweet#source-labels) which in my understanding is determined by the credentials provided when the POST statuses/update request is made to the twitter-api. This name/source is for example shown below a tweet in the Twitter-Web-App or the Android App or in the twitter-app authorization screen. Every source is registered by one specific twitter-developer-account. Therefore it should not be possible to use invisible characters in an app-name, because names would stop 'looking' unique. If you try for example to register a app with a name which includes a 'zero width space' (U+200B) you get the following error: "appName: The application name can't include invisible unicode characters". Despite this warning it's possible to use the 'mongolian vowel separator' U+180E within a app-name. The name is rendered like the name without this symbol (I tested this at least with the twitter-web app in Chrome on Windows and in Twitter for Android), but it's registered as a completely different application. Notice that a possible attack scenario, which is a bit more detactable, is using other unicode spaces for example from... ...



๐Ÿ“Œ Twitter: Twitter Source Label allow 'mongolian vowel separator' U+180E (app name)


๐Ÿ“ˆ 187.17 Punkte

๐Ÿ“Œ Quest Policy Authority 8.1.2.200 submitUser.jsp first name/last name/logon name cross site scripting


๐Ÿ“ˆ 23.85 Punkte

๐Ÿ“Œ CVE-2022-3493 | SourceCodester Human Resource Management System 1.0 Add Employee First Name/Middle Name/Last Name cross site scripting


๐Ÿ“ˆ 23.85 Punkte

๐Ÿ“Œ CVE-2022-3518 | SourceCodester Sanitization Management System 1.0 User Creation First Name/Middle Name/Last Name cross site scripting


๐Ÿ“ˆ 23.85 Punkte

๐Ÿ“Œ CVE-2022-3716 | SourceCodester Online Medicine Ordering System 1.0 First Name/Middle Name/Last Name cross site scripting


๐Ÿ“ˆ 23.85 Punkte

๐Ÿ“Œ CVE-2024-0782 | CodeAstro Online Railway Reservation System 1.0 pass-profile.php First Name/Last Name/User Name cross site scripting


๐Ÿ“ˆ 23.85 Punkte

๐Ÿ“Œ [local] - MacOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Best company name ever! Share capital ยฃ1, name pricelessโ€ฆ


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ [local] - MacOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Best company name ever! Share capital ยฃ1, name pricelessโ€ฆ


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ setroubleshoot bis 3.2.22 sealert fix_lookup_id File Name Name erweiterte Rechte


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Should Domain-Name Registrations Require A Verifiable Real Name?


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Should Domain-Name Registrations Require A Verifiable Real Name?


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Brickhost phpScheduleIt 1.0 Rc1 Name/Lastname/Schedule Name cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ setroubleshoot up to 3.2.22 sealert fix_lookup_id File Name Name privilege escalation


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Statamic 2.10.3 Add New /users First Name/Last Name cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ [dos] Dnss Domain Name Search Software - 'Name' Denial of Service (PoC)


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Jirafeau bis 3.4.0 Search by Name name Cross Site Scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Yahoo! Messenger up to 5.6.0.1358 File Name Long File Name memory corruption


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ #0daytoday #Dnss Domain Name Search Software - (Name) Denial of Service Exploit [dos #exploits #0day #Exploit]


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Jirafeau up to 3.4.0 Search by Name name cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall hotel-booking-script 2.0.4 First Name/Last Name/Address field denial of service


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall hotel-booking-script 2.0.4 First Name/Last Name/Address field cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall Basic B2B Script 2.0.0 First name/Last name/Address 1/City/State/Company Reflected cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall Basic B2B Script 2.0.0 First name/Last name/Address 1/City/State/Company Reflected Cross Site Scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Monstra CMS 3.0.4 Edit Profile first name/last name cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ TIL that the name of ubuntu linux distro comes from the name of an african philosofy meaning ''I am because we are''


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ Is having your first name and last name in your email address a bad thing?


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall Basic B2B Script 2.0.9 First Name/Last Name HTML Injection cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 First Name/Last Name Javascript denial of service


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ PHP Scripts Mall Advance B2B Script 2.1.4 FIRST NAME/LAST NAME Stored cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ CentOS Web Panel 0.9.8.789 DNS Functions Name Server 1/Name Server 2 Persistent cross site scripting


๐Ÿ“ˆ 15.9 Punkte

๐Ÿ“Œ CreatiWity wityCMS 0.6.2 utilisateur Menu first name/last name cross site scripting


๐Ÿ“ˆ 15.9 Punkte











matomo