
A bug in Twitter about how it handles password reminders allowed users to take control of other accounts such as @emoji and @god.

Usually if a user went to reset a password, it would partially asterisking the mail out, however this time it displayed the full email address tied to it.

This allowed hackers to hijack many accounts and tweet on their behalf, but majority of accounts that were soon taken over were restored to normal.


"id": "TWI13217522",
"linkid": "twitter",
"type": "Vulnerability",
"date": "02/2016",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"