Home > News > Massive Security Breach Found on Facebook and MySpace • Bookmark   • Newsletters   • Register Search Options

NEWS STORY

Massive Security Breach Found on Facebook and MySpace

Massive Security Breach Found on Facebook and MySpace
Get XBIZ News
XBIZ Research
Should governments have the power / ability to stop content piracy? (e.g. SOPA / PROTECT IP)
Yes
  45.45%
No
  45.02%
Undecided
  9.52%
Out of 231 votes. Results based on votes submitted by members of XBIZ.net social network.
Thursday, Nov 5, 2009    Text size: 
CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

More ways to get XBIZ News:  RSS Feeds  |  E-Newsletters  |  Desktop Widget  |  Mobile
Looking for porn star news and behind-the-scene videos? Check out XFANZ.com !

QUICKBITE FEATURES

Venus Intimate: Refreshed Focus

The European trade show market has been split in two in a move similar to that which toy manufacturers, retailers and buyers already have experienced in the U.S. With the longrunning VENUS show taking... More »

An Android Ice Cream Sandwich

Google recently released its highly anticipated and extensively revamped Android 4.0 mobile operating system (OS), codenamed “Ice Cream Sandwich,” much to the delight of users of phones, tablets... More »

Seasonal Success

The adult retail industry has embarked on its lengthy holiday season — starting with Halloween and extending to Valentine’s Day. XBIZ spoke with Camilla Lombard, events and publicity manager... More »
XBIZ NEWSLETTERS
Stay informed of the latest industry developments. Get XBIZ newsletters delivered to your inbox. Subscribe today!
Enter email address:

* To manage existing subscriptions click here.






POPULAR PRODUCTS & SERVICES
Submit your press release to
multiple news outlets with 1 click.
Subscribe to RSS news feeds or
add free content to your website.
Access XBIZ news and articles
with your mobile device.
XBIZ World™, the industry's leading technology journal, provides in-depth coverage of company news, market trends, growth sectors, and international news in the online, mobile and ancillary sectors - get it today!

UPCOMING EVENTS

XBIZ London Gathering

Feb 23 - Feb 23
Truckles Wine Bar in Holborn

Adult Entertainment Virtual Convention

Feb 24 - Feb 26
World Wide Web

The European Summit

Mar 05 - Mar 08
Barcelona, Spain

International Lingerie Show

Mar 26 - Mar 28
Las Vegas, Nevada
Everyday thousands of business professionals browse XBIZ's industry directory for quality products and services. Not listed yet? Your company could be losing potential new business. Submit your company today!
Use XBIZ RSS feeds to stay informed of the latest industry developments or as a content syndication tool for your website!