WHID 2009-4: Twitter Personal Info CSRF

Updated: 
13 January 2009
Attack Information
WHID ID: 
2009-4
Date Occured: 
7 Jan 2009
Outcome Information
Target Information
Attacked Entity Field: 
Web 2.0
Attacked Entity Geography: 
USA
Source Information
Attack Source Geography: 
Italy

Gareth Heyes (and others) reported an interesting vulnerability in Twitter last week. While his post included a proof of concept code, it does not qualify as a hack only a vulnerability disclosure and the Web Hacking Incident Database does not list vulnerabilities.

Luckily Cool Giorgio Maone decided to create his own proof of concept, run it himself and provide us with the result, enabling me to label this as a hack

By exploiting a CSRF bug in twitter (or maybe a feature?) site owners can get twitter profiles of their visitors. For Twitter this is a second this year and now the comprise 50% of the web incidents for 2009. Is this going to be the year of Web 2.0 security?