Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2025 XBIZ Amsterdam Website Launches With Call for Speakers

XBIZ is pleased to announce that the website for its annual European conference, XBIZ Amsterdam, is now live.

NC Governor Vetoes Bill Targeting Adult, Could Face Override

North Carolina Governor Josh Stein today vetoed a bill imposing new regulations that adult industry observers have warned could push adult websites and platforms to ban most adult creators and content.

25,000 Sign Petition to Legalize Pornography in Ukraine

An OnlyFans model’s petition to decriminalize pornography in Ukraine has amassed the 25,000 signatures required for official consideration by President Volodymyr Zelensky.

WannaCollab Joins Pineapple Support as Supporter-Level Sponsor

WannaCollab has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

FSC Unpacks SCOTUS Age Verification Ruling in Webinar

The Free Speech Coalition conducted a public webinar Tuesday to help adult industry stakeholders understand the Supreme Court’s recent decision in FSC v. Paxton, and its potential implications.

UK Lawmaker Calls for Appointment of 'Porn Minister'

Baroness Gabrielle Bertin, the Conservative member of Parliament who recently convened a new anti-pornography task force, is calling for the appointment of a “minister for porn,” according to British news outlet The Guardian.

FSC Toasts Jeffrey Douglas for 30 Years of Service

n the very same evening when the adult industry was hit hard by the Supreme Court ruling supporting Texas’ controversial age verification law, HB 1181, members of the Free Speech Coalition board, staff and supporters gathered to celebrate Jeffrey Douglas’ 30 years as board chair — a fitting reflection of his reputation as an eternal optimist.

TTS Opens UK Testing Location

Talent Testing Service (TTS) has opened a new U.K. location in Ware, Hertfordshire.

FSC: Age-Verification Laws Go Into Effect in South Dakota, Georgia, Wyoming on July 1

The Free Speech Coalition (FSC) has published a statement regarding new age verification laws set to go into effect tomorrow in South Dakota, Georgia, and Wyoming.

FSC Responds to Supreme Court Decision on Texas AV Law

The Free Speech Coalition (FSC) has released a statement responding to last week's Supreme Court decision on FSC v. Paxton, the Texas age verification law.

Show More