When you sign up for application, you can authorize some domains. Then, instead of adding domains, you add some malicious code into the form.
I found it today and reported it to twitter.
No comments:
Post a Comment