Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

MojoHost Reaffirms Commitment to Adult Industry Amid Project 2025 Implications

In the wake of Tuesday's election and amid concerns about the possible ramifications for the adult industry, MojoHost President Brad Mitchell has releases a statement addressing Project 2025 and the future of the industy.

Adult Web Hosting Service 'Midnight-Host' Launches

Midnight-Host, a new web hosting service designed specifically for adult websites, has launched.

ASN Lifestyle Magazine Joins Pineapple Support as Media Sponsor

ASN Lifestyle Magazine has joined the ranks of over 60 adult businesses and organizations committing funds and resources to Pineapple Support, partnering with the organization as a media sponsor.

Adult Industry Reacts to Trump Victory

On Tuesday, former President Donald Trump was reelected, defeating Vice President Kamala Harris to reclaim the office he lost four years ago.

Fetisfy Online Fetish Marketplace Launches

Fetisfy.com, an online marketplace for users to sell fetish items, has launched.

Pineapple Support Launches 'Spill the Tea, Colombia' Community Support Event Series

Pineapple Support has launched "Spill the Tea, Colombia," a monthly, in-person community support event for adult industry professionals.

Streamster Launches 'Tip2Peep' Camera-Switching Feature

Live-streaming software provider Streamster has launched Tip2Peep, a new feature that allows viewers to switch between multiple webcam viewing angles by tipping the creator.

Tyler Wu Guests on Chaturbate's 'Sex Tales' Podcast

Tyler Wu is the latest guest on Chaturbate’s “Sex Tales” podcast, hosted by Melissa Stratton and Vanniall on the company’s “Camming Life” YouTube channel.

Fleshy to Launch Interactive Cam Site 'Eromote'

Male pleasure brand Fleshy has announced that it will launch an interactive, bidirectional cam site next month called Eromote.

XBIZ LA Show Introduces New 'Crib Crawl' Feature

XBIZ is pleased to announce that the 2025 edition of its flagship conference, the XBIZ Show, will debut a brand-new feature: Crib Crawl, offering attendees the chance to meet and greet representatives from leading brands and organizations in dedicated suites at the host venue.

Show More