Developer Uncovers Major Hole in Twitter Security

LOS ANGELES — An independent developer has exposed a massive security hole in the microblogging website Twitter that remains a problem.

UK-based developer Dave Naylor revealed yesterday that malicious users can insert a simple bit of code into one of Twitter's text fields. These fields, boxes usually reserved for users to insert links, can simultaneously accept other kinds of code that can direct the site to steal cookies, create worms or otherwise propagate malware to Twitter's considerable user base.

Naylor, who specializes in search-engine optimization, discovered the error and alerted Twitter's brass. Today news has spread that the problem remains unaddressed.

"With a few minutes work, someone with a bit of technical expertise could make a Twitter ‘application’ and start sending tweets with it," Naylor said. "Using the simple instructions below, it can be arranged so that if another Twitter user so much as sees one of these tweets - and they are logged in to Twitter — their account could be taken over."

Naylor added that hackers have many options at their disposal for such malicious applications. They could conceivably redirect browsers to other destinations, erase all of a user's data or start spamming that user's contacts list.

According to online reports, Twitter officials never got in touch with Naylor to discuss the problem or a solution to it.

"In my opinion, it’s completely unacceptable that Twitter engineers never got in touch with Naylor to learn more about the exploit and adequately fix the problem, which the SEO consultant correctly marks a shame. Instead, the startup’s tech team apparently tried fixing it without really looking at the potential security issues," said tech analyst Robin Wauters of TechCrunch.com.

Last month, high-level Twitter officials had their accounts compromised by a hacker who figured out the answers to the security questions associated with their webmail accounts. In addition, word broke that Twitter's primary database was password protected with the code "password."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Fanso.io Expands Payment Options With Centrobill Partnership

Payment services provider Centrobill and turnkey subscription platform builder Fanso have partnered to enhance payment options for online marketplace businesses using the Fanso script.

Sara Jay, Dan Leal to Co-Host Heineken Brewery Tour, XBIZ Amsterdam 'Performers' Rights' Panel

Sara Jay and "Porno" Dan Leal will co-host a tour of the historic Heineken brewing factory on Tuesday, Sept. 3 at 1 p.m., during the XBIZ Amsterdam conference.

Vixen, Julmodels to Host 'Club Vixen' Party at XBIZ Amsterdam

Vixen Media Group and premier European talent agency Julmodels will once again team up to host a lavish party at XBIZ Amsterdam: Club Vixen, set to take place the evening of Sept. 4.

Cherie DeVille Lambasts Laila Mickelwait's Anti-Pornhub Book in New Op-Ed

2023 XBIZ Performer of the Year Cherie DeVille has penned a new opinion piece for The Daily Beast, about a new book by religiously motivated anti-Pornhub crusader Laila Mickelwait.

TheArtemiXXX Launches Through YourPaysitePartner

Content creator Artemis Spiegel has launched his new site, TheArtemiXXX.com, through YourPaysitePartner (YPP).

Federal Prosecutors Seek 20-Year Sentences for Remaining Backpage Defendants

Federal prosecutors asked on Monday that the three remaining defendants in the protracted Backpage.com case in Arizona be sentenced to 20 years in prison each.

AI-Powered Chat Service 'Fanalytics' Launches

AI-powered chat service Fanalytics has debuted, aimed at OnlyFans content creators and agencies.

AEBN Publishes Popular Searches by Country for June, July

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during June and July.

Sansyl to Host 'All Out' Opening Night Bash at XBIZ Amsterdam

The Sansyl Group, the Dutch parent company of PayBig, has signed on to sponsor the official opening night party of XBIZ Amsterdam.

FSC: California's Porn Age Verification Bill Defeated Over Budget Concerns

The California legislature’s age verification bill, one of numerous AV bills being sponsored around the country by anti-porn activists, will not be moving forward, Free Speech Coalition reported Tuesday.

Show More