Developer Uncovers Major Hole in Twitter Security

LOS ANGELES — An independent developer has exposed a massive security hole in the microblogging website Twitter that remains a problem.

UK-based developer Dave Naylor revealed yesterday that malicious users can insert a simple bit of code into one of Twitter's text fields. These fields, boxes usually reserved for users to insert links, can simultaneously accept other kinds of code that can direct the site to steal cookies, create worms or otherwise propagate malware to Twitter's considerable user base.

Naylor, who specializes in search-engine optimization, discovered the error and alerted Twitter's brass. Today news has spread that the problem remains unaddressed.

"With a few minutes work, someone with a bit of technical expertise could make a Twitter ‘application’ and start sending tweets with it," Naylor said. "Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter — their account could be taken over."

Naylor added that hackers have many options at their disposal for such malicious applications. They could conceivably redirect browsers to other destinations, erase all of a user's data or start spamming that user's contacts list.

According to online reports, Twitter officials never got in touch with Naylor to discuss the problem or a solution to it.

"In my opinion, it’s completely unacceptable that Twitter engineers never got in touch with Naylor to learn more about the exploit and adequately fix the problem, which the SEO consultant correctly marks a shame. Instead, the startup’s tech team apparently tried fixing it without really looking at the potential security issues," said tech analyst Robin Wauters of TechCrunch.com.

Last month, high-level Twitter officials had their accounts compromised by a hacker who figured out the answers to the security questions associated with their webmail accounts. In addition, word broke that Twitter's primary database was password protected with the code "password."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Summit Event Schedule Announced

Free Speech Coalition (FSC) has revealed its slate of networking events and symposiums for its annual summit, set for January 15 during XBIZ 2026.

Pornhub Releases 2025 'Year in Review' Report

Pornhub has released its “Year in Review Insights” report for 2025, the 12th edition of the site’s annual statistics, data analysis, and infographic initiative.

Washington AV Bill Jumps on 'Health Warning' Bandwagon

A new age verification bill in the Washington state legislature would require adult sites to post notices warning users of alleged health risks, despite a previous federal court ruling against such requirements.

BranditScan Launches '25 Days of Christmas' Promo

BranditScan has launched its 25 Days of Christmas promotion.

MelRose Michaels Named Host of Online Industry Edition of XBIZ Honors

Performer and entrepreneur MelRose Michaels will MC the online industry edition of the 2026 XBIZ Honors, set for Wednesday, Jan. 14, at the Kimpton Everly Hotel in Hollywood.

Irish Regulator: EU States to Ramp Up AV Enforcement for Smaller Sites

A representative of Irish media regulator Coimisiún na Meán told legislators that Ireland and other EU states are preparing to expand enforcement of age verification regulations to include smaller adult sites, British newspaper The Times is reporting.

Sansyl Group Acquires Blue Donkey Media

Sansyl Group, parent company of AdultPrime Network, has acquired Blue Donkey Media B.V., owner of Dutch adult site Meiden van Holland, among several other erotic websites and television channels.

Pineapple Support to Hold Mental Health Summit

The annual Pineapple Support Mental Health Summit is taking place Dec. 15-17.

Ofcom Fines AVS Group $1.3 Million for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed a penalty of one million pounds, or approximately $1.3 million, on AVS Group Ltd. after an investigation concluded that the company had failed to implement robust age checks on 18 adult websites.

Updated: Aylo to Help Test EU Age Verification App

Pornhub parent company Aylo plans to participate in the European Commission’s pilot program for its “white label” age verification app, a spokesperson for the company has confirmed.

Show More