Developer Uncovers Major Hole in Twitter Security

LOS ANGELES — An independent developer has exposed a massive security hole in the microblogging website Twitter that remains a problem.

UK-based developer Dave Naylor revealed yesterday that malicious users can insert a simple bit of code into one of Twitter's text fields. These fields, boxes usually reserved for users to insert links, can simultaneously accept other kinds of code that can direct the site to steal cookies, create worms or otherwise propagate malware to Twitter's considerable user base.

Naylor, who specializes in search-engine optimization, discovered the error and alerted Twitter's brass. Today news has spread that the problem remains unaddressed.

"With a few minutes work, someone with a bit of technical expertise could make a Twitter ‘application’ and start sending tweets with it," Naylor said. "Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter — their account could be taken over."

Naylor added that hackers have many options at their disposal for such malicious applications. They could conceivably redirect browsers to other destinations, erase all of a user's data or start spamming that user's contacts list.

According to online reports, Twitter officials never got in touch with Naylor to discuss the problem or a solution to it.

"In my opinion, it’s completely unacceptable that Twitter engineers never got in touch with Naylor to learn more about the exploit and adequately fix the problem, which the SEO consultant correctly marks a shame. Instead, the startup’s tech team apparently tried fixing it without really looking at the potential security issues," said tech analyst Robin Wauters of TechCrunch.com.

Last month, high-level Twitter officials had their accounts compromised by a hacker who figured out the answers to the security questions associated with their webmail accounts. In addition, word broke that Twitter's primary database was password protected with the code "password."

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

BranditScan Rolls Out 2 New Platform Features

BranditScan has introduced its new Traffic Optimization and Doxing Protection features for creators.

NMG Management Partners With Cosplayground to Scale Distribution

NMG Management has partnered with Cosplayground to expand the studio’s digital distribution and licensing operations.

Dreamcam Rolls Out 'Voice Translator AI'

Dreamcam has introduced a Voice Translator AI to its livestreaming platform.

UK Government May Limit 'Step' Porn Ban With New Amendments

The U.K. Ministry of Justice on Friday revealed new government amendments to the pending Crime and Policing Bill, potentially limiting a pending ban on “step” content to apply only if adult performers role-play as minors.

Arizona Senate Removes 'Catch-22' Provision From Consent Bill

The Arizona State Senate has amended a bill that would impose new requirements for adult content uploaded online, removing a seemingly contradictory provision that could have effectively made it impossible for adult sites to operate in the state.

Climaxx Media Launches Networking Platform

Climaxx Media has officially launched its new networking platform.

Italian Court in Aylo Case Limits International Reach of AV Rules

An Italian administrative court has ruled that Italy’s recently-enacted age verification rules for adult content may not currently be enforced against sites based in other EU member states, pending further procedural action under the EU’s Directive on Electronic Commerce.

OCC, FDIC Prohibit Use of 'Reputation Risk' by Regulators

The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) on Tuesday issued a final rule codifying the elimination of ‘reputation risk’ as a criterion in their supervision of financial institutions.

Wisconsin Governor Vetoes Age Verification Bill

Gov. Tony Evers on Friday vetoed AB 105, an age verification bill that would have allowed anyone to sue adult content providers for damages over alleged failure to age-verify users in Wisconsin, with penalties of up to $10,000 per violation.

FSC Releases Statement on Wisconsin Governor Vetoing AV Bill

The Free Speech Coalition has released a statement on Wisconsin Governor Tony Evers' veto of the state's age verification legislation.

Show More