Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Industry Photog, 'Payout' Founder Mike B Passes Away

Longtime industry photographer and publisher Michael Bartholomey, known widely as Mike B, passed away Saturday.

FSC Announces 2025 Board of Directors Election Nominees

The Free Speech Coalition (FSC) has announced the nominees for its 2025 Board of Directors election.

AdultHTML Launches Black Friday Web Design, Development Promo

AdultHTML has launched its annual Black Friday/Cyber Monday promo for web design and development, running through Dec. 5.

Canada Exempts Online Adult Content From 'CanCon' Quotas

The Canadian Radio-television and Telecommunications Commission (CRTC) has updated its broadcasting regulatory policies, exempting streaming adult content from “made in Canada” requirements that apply to other online material.

Creator Law Firm 'OnlyFirm' Launches

Entertainment attorney Alex Lonstein has officially launched OnlyFirm.com for creators.

German Court Puts Pornhub, YouPorn 'Network Ban' on Hold

The Administrative Court of Düsseldorf has temporarily blocked the State Media Authority of North Rhine-Westphalia (LfM) from forcing telecom providers to cut off access to Aylo-owned adult sites Pornhub and YouPorn.

FSC: NC Law Invalidating Model Contracts Takes Effect December 1

The Free Speech Coalition (FSC) announced today that North Carolina's Prevent Exploitation of Women and Minors Act goes into effect on December 1.The announcement follows:

Ofcom Investigates More Sites in Wake of AV Traffic Shifts

U.K. media regulator Ofcom has launched investigations into 20 more adult sites as part of its age assurance enforcement program under the Online Safety Act.

MintStars Launches Debit Card for Creators

MintStars has launched its MintStars Creator Card, powered by Payy.

xHamster Settles Texas AV Lawsuit, Pays $120,000

Hammy Media, parent company of xHamster, has settled a lawsuit brought by the state of Texas over alleged noncompliance with the state’s age verification law, agreeing to pay a $120,000 penalty.

Show More