Developer Uncovers Major Hole in Twitter Security

LOS ANGELES — An independent developer has exposed a massive security hole in the microblogging website Twitter that remains a problem.

UK-based developer Dave Naylor revealed yesterday that malicious users can insert a simple bit of code into one of Twitter's text fields. These fields, boxes usually reserved for users to insert links, can simultaneously accept other kinds of code that can direct the site to steal cookies, create worms or otherwise propagate malware to Twitter's considerable user base.

Naylor, who specializes in search-engine optimization, discovered the error and alerted Twitter's brass. Today news has spread that the problem remains unaddressed.

"With a few minutes work, someone with a bit of technical expertise could make a Twitter ‘application’ and start sending tweets with it," Naylor said. "Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter — their account could be taken over."

Naylor added that hackers have many options at their disposal for such malicious applications. They could conceivably redirect browsers to other destinations, erase all of a user's data or start spamming that user's contacts list.

According to online reports, Twitter officials never got in touch with Naylor to discuss the problem or a solution to it.

"In my opinion, it’s completely unacceptable that Twitter engineers never got in touch with Naylor to learn more about the exploit and adequately fix the problem, which the SEO consultant correctly marks a shame. Instead, the startup’s tech team apparently tried fixing it without really looking at the potential security issues," said tech analyst Robin Wauters of TechCrunch.com.

Last month, high-level Twitter officials had their accounts compromised by a hacker who figured out the answers to the security questions associated with their webmail accounts. In addition, word broke that Twitter's primary database was password protected with the code "password."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2025 XBIZ Amsterdam Website Launches With Call for Speakers

XBIZ is pleased to announce that the website for its annual European conference, XBIZ Amsterdam, is now live.

NC Governor Vetoes Bill Targeting Adult, Could Face Override

North Carolina Governor Josh Stein today vetoed a bill imposing new regulations that adult industry observers have warned could push adult websites and platforms to ban most adult creators and content.

25,000 Sign Petition to Legalize Pornography in Ukraine

An OnlyFans model’s petition to decriminalize pornography in Ukraine has amassed the 25,000 signatures required for official consideration by President Volodymyr Zelensky.

WannaCollab Joins Pineapple Support as Supporter-Level Sponsor

WannaCollab has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

FSC Unpacks SCOTUS Age Verification Ruling in Webinar

The Free Speech Coalition conducted a public webinar Tuesday to help adult industry stakeholders understand the Supreme Court’s recent decision in FSC v. Paxton, and its potential implications.

UK Lawmaker Calls for Appointment of 'Porn Minister'

Baroness Gabrielle Bertin, the Conservative member of Parliament who recently convened a new anti-pornography task force, is calling for the appointment of a “minister for porn,” according to British news outlet The Guardian.

FSC Toasts Jeffrey Douglas for 30 Years of Service

n the very same evening when the adult industry was hit hard by the Supreme Court ruling supporting Texas’ controversial age verification law, HB 1181, members of the Free Speech Coalition board, staff and supporters gathered to celebrate Jeffrey Douglas’ 30 years as board chair — a fitting reflection of his reputation as an eternal optimist.

TTS Opens UK Testing Location

Talent Testing Service (TTS) has opened a new U.K. location in Ware, Hertfordshire.

FSC: Age-Verification Laws Go Into Effect in South Dakota, Georgia, Wyoming on July 1

The Free Speech Coalition (FSC) has published a statement regarding new age verification laws set to go into effect tomorrow in South Dakota, Georgia, and Wyoming.

FSC Responds to Supreme Court Decision on Texas AV Law

The Free Speech Coalition (FSC) has released a statement responding to last week's Supreme Court decision on FSC v. Paxton, the Texas age verification law.

Show More