Loading HuntDB...

Bypass t.co link shortener in Twitter direct messages

Low
X
X (Formerly Twitter)
Submitted None

Team Summary

Official summary from X (Formerly Twitter)

The researcher demonstrated a way to create a link that will not be replaced with safe shortened t.co url, by sending Direct Messages containing more than 50 t.co links to another Twitter user. If the recipient views the message using Twitter’s Android app, and clicks the 51st link in the attacker’s message, they will be redirected to the target website without first passing through Twitter’s t.co link shortener.

Reported by iambouali

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors