Seriously, their response was to disable spaces in the form?
There is no legitimate reason for anything other than \w to be in there... how about a real filter? Twitter has been lazy and generally pathetic in just about every area since they began... talk about getting lucky with a good idea.
The substitution they do is <a href="%s">, and you can "game that" by inserting 'http://foo.com> other stuff goes here <whatever foo="">' Fine. The literal HTML that the user sees becomes '<a href="http://foo.com>other stuff goes here <whatever foo="">'. That's bad.
Now if you escape that properly, you get: '<a href="http://foo.com&quot;&gt; other stuff goes here &lt;whatever foo=&quot;">' Garbage, but not a security problem.
(BTW, news.arc fucks up the escaping too, so this example is garbage. Sorry. See nopaste here: http://scsys.co.uk:8001/33063
Edit: sigh, that is also broken! Bottom line; none of these things will happen to you if you replace every & with &amp;, every " with &quot;, every ' with &apos;, every < with &lt; and every > with &gt;.)
On the YC submission thread created when this vulnerability was first noticed there were several good solutions suggested for this problem. al3x from Twitter responded to several of the comments and if memory serves he thought several of the solutions would work.
For a halfway decent coder this could be solved in minutes. This has nothing to do with maintaining a huge website as some users have commented. Stuff like this should probably break less when your website is huge.
There is no legitimate reason for anything other than \w to be in there... how about a real filter? Twitter has been lazy and generally pathetic in just about every area since they began... talk about getting lucky with a good idea.