Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

MomPOV Producer Pleads Guilty in GirlsDoPorn Case

MomPOV producer Doug Wiederhold, who was formerly the partner of GirlsDoPorn owner Michael Pratt as well as the first male talent for GDP, pleaded guilty Thursday to a federal conspiracy charge.

Streamate Exec Liz Rek Joins FSC Board

The Free Speech Coalition board of directors has tapped Streamate executive Liz Rek as its newest member, effective immediately.

2024 XBIZ Creator Awards Nominees Announced; Voting Now Live

XBIZ is pleased to announce the nominees for the 2024 XBIZ Creator Awards, presented by Fansly.

Adult Site Broker Talk's Bruce Friedman Reflects on Podcast Success

The 200th episode of “Adult Site Broker Talk” will air next week, with 2023 XBIZ Performer of the Year Cherie DeVille as the featured guest.

FSC Asks Supreme Court to Overturn 5th Circuit Decision, Strike Texas' Age Verification Law

Free Speech Coalition (FSC) filed a petition for certiorari on Friday asking the U.S. Supreme Court to overturn the Fifth Circuit panel decision that partially upheld Texas’ controversial age verification law.

Details Emerge About Capture, Arrest of GirlsDoPorn's Michael Pratt

Further details have emerged in the past week about the capture and arrest of GirlsDoPorn owner Michael Pratt in Spain in December 2022, following his extradition to the U.S. last month.

Magdalene St. Michaels, Andy Rodrigues Named as AEBN Top Stars for Q1 of 2024

AEBN has announced its top-selling stars for the first quarter of 2024, with Magdalene St. Michaels landing atop the leader board for straight theaters and Andy Rodrigues heading up the gay rankings.

YouPay Partners With IP Security Solution Sidenty

Australian gifting platform YouPay has joined forces with IP security solution Sidenty to help creators guard against online theft and unauthorized use of their content.

Grooby Launches Fetish Site 'Joey's Trans Feet Girls'

Grooby has debuted Joey's Trans Feet Girls, a new fetish membership site featuring foot content by top trans performers.

Lady Lyne Launches New Paysite Through AdultPrime

IMC’s AdultPrime has expanded its network of paysites with the launch performer Lady Lyne's official site.

Show More