Stealing User emails by clickjacking cards.twitter.com/xxx/xxx

Disclosed: 2017-02-03 16:14:43 By akhil-reni To x
Medium
Vulnerability Details
**Hello** In twitter you can create cards to generate leads. For example: https://twitter.com/i/cards/tfw/v1/759046372544741376?cardname=promotion&autoplay_disabled=true&earned=true&lang=en&card_height=357 If you visit the above URL and click the button your email and username is sent to my domain. Since this page is missing X-FRAME-HEADERS, a user could simply iframe the URL and could steal victim's emails. **Proof of concept code** ``` <html> <iframe src=https://twitter.com/i/cards/tfw/v1/759046372544741376?cardname=promotion&autoplay_disabled=true&earned=true&lang=en&card_height=357> </html> ``` **Regards, Akhil**
Actions
View on HackerOne
Report Stats
  • Report ID: 154963
  • State: Closed
  • Substate: resolved
  • Upvotes: 49
Share this report