There has been at least one blog post already describing more about this vulnerability and how to exploit it. Please don't link to it.
-
-
Replying to @steveklabnik
@steveklabnik there's totally this secret blog post you might be able to find if you look, but if you find it, please, don't link to it ;)4 replies 0 retweets 1 like -
Replying to @bascule2 replies 0 retweets 0 likes
-
Replying to @steveklabnik
@steveklabnik@bascule I think Responsible Disclosure is near impossible. Once 'the bad guys' figure out the vuln the info embargoes fail.1 reply 0 retweets 0 likes -
Replying to @miah_
@miah_@steveklabnik or once the good guys figure it out and tweet about it? whoops ;)1 reply 0 retweets 0 likes -
Replying to @bascule
@bascule@steveklabnik Pretty much. Its difficult to get people to actually patch their systems in the first place.1 reply 0 retweets 0 likes
Replying to @miah_
@miah_ @steveklabnik FWIW, @livingsocial patched last Thursday
1:16 PM - 8 Jan 2013
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.