Home > News > Developer Uncovers Major Hole in Twitter Security • Bookmark   • Newsletters   • Register Search Options

NEWS STORY

Developer Uncovers Major Hole in Twitter Security

Developer Uncovers Major Hole in Twitter Security
Get XBIZ News
XBIZ Research
Should governments have the power / ability to stop content piracy? (e.g. SOPA / PROTECT IP)
Yes
  45.45%
No
  45.02%
Undecided
  9.52%
Out of 231 votes. Results based on votes submitted by members of XBIZ.net social network.
Thursday, Aug 27, 2009    Text size: 
LOS ANGELES — An independent developer has exposed a massive security hole in the microblogging website Twitter that remains a problem.

UK-based developer Dave Naylor revealed yesterday that malicious users can insert a simple bit of code into one of Twitter's text fields. These fields, boxes usually reserved for users to insert links, can simultaneously accept other kinds of code that can direct the site to steal cookies, create worms or otherwise propagate malware to Twitter's considerable user base.

Naylor, who specializes in search-engine optimization, discovered the error and alerted Twitter's brass. Today news has spread that the problem remains unaddressed.

"With a few minutes work, someone with a bit of technical expertise could make a Twitter ‘application’ and start sending tweets with it," Naylor said. "Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter — their account could be taken over."

Naylor added that hackers have many options at their disposal for such malicious applications. They could conceivably redirect browsers to other destinations, erase all of a user's data or start spamming that user's contacts list.

According to online reports, Twitter officials never got in touch with Naylor to discuss the problem or a solution to it.

"In my opinion, it’s completely unacceptable that Twitter engineers never got in touch with Naylor to learn more about the exploit and adequately fix the problem, which the SEO consultant correctly marks a shame. Instead, the startup’s tech team apparently tried fixing it without really looking at the potential security issues," said tech analyst Robin Wauters of TechCrunch.com.

Last month, high-level Twitter officials had their accounts compromised by a hacker who figured out the answers to the security questions associated with their webmail accounts. In addition, word broke that Twitter's primary database was password protected with the code "password."

More ways to get XBIZ News:  RSS Feeds  |  E-Newsletters  |  Desktop Widget  |  Mobile
Looking for porn star news and behind-the-scene videos? Check out XFANZ.com !

LEGAL PERSPECTIVES

Need for Serious Value in Content

Most adult entertainment business owners know that distributing sexually explicit materials exposes them to the possibility of prosecution for violation of obscenity laws. But while many know that the... More »

Romney? Perry? 5 Things to Prepare for

It’s the fall of 2011, and the U.S. unemployment rate is at 9.1 percent and the economy appears too many to be heading back into recession. It is not surprising that President Obama’s approval... More »

Killing the Messenger: The Campaign Against Online Escort Advertising Sites

The recent guilty plea by Escorts.com has ignited interest in the legal issues surrounding the operation of an online escort site.  In this two-part blog post, the author will examine real-world examples... More »
XBIZ NEWSLETTERS
Stay informed of the latest industry developments. Get XBIZ newsletters delivered to your inbox. Subscribe today!
Enter email address:

* To manage existing subscriptions click here.






POPULAR PRODUCTS & SERVICES
Submit your press release to
multiple news outlets with 1 click.
Subscribe to RSS news feeds or
add free content to your website.
Access XBIZ news and articles
with your mobile device.
Access the latest issues of the industry's premier trade journals in digital format - view online or download for offline viewing!

UPCOMING EVENTS

XBIZ London Gathering

Feb 23 - Feb 23
Truckles Wine Bar in Holborn

Adult Entertainment Virtual Convention

Feb 24 - Feb 26
World Wide Web

The European Summit

Mar 05 - Mar 08
Barcelona, Spain

International Lingerie Show

Mar 26 - Mar 28
Las Vegas, Nevada
Everyday thousands of business professionals browse XBIZ's industry directory for quality products and services. Not listed yet? Your company could be losing potential new business. Submit your company today!
Use XBIZ RSS feeds to stay informed of the latest industry developments or as a content syndication tool for your website!