Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Strike 3 Holdings Sues Meta for Pirating Vixen Media Group Content to Train AI

Vixen Media Group owner Strike 3 Holdings filed suit in federal court this week, accusing Facebook parent company Meta of copyright infringement and alleging that Meta has extensively pirated VMG content to train its artificial intelligence models.

Pineapple Support, Streamate to Host 'Navigating Grief and Loss' Support Group

Pineapple Support and Streamate are hosting a free online support group to help performers cope with grief and loss.

Friday is Final AV Compliance Deadline in UK

Friday, July 25 marks U.K. media regulator Ofcom’s deadline for user-to-user services such as tube, cam and fan sites to implement its requisite “highly effective age assurance” measures for preventing minors from viewing adult content.

AEBN Publishes Popular Searches for May, June

AEBN has released the top search terms for the months of May and June from its straight and gay theaters in all 50 states and the District of Columbia.

Ofcom Releases Transparency Reporting Guidelines

Ofcom, the U.K. media regulator, has made public its official guidance detailing how online service providers — including adult sites — will be required to publish annual transparency reports on their efforts to protect children from online harms.

New AV Rules Take Effect for Ireland-Based Sites

Ireland’s Online Safety Code came into force Monday, including a provision requiring adult sites headquartered in Ireland to implement age assurance measures beyond self-declaration.

XBIZ Amsterdam Calls on New Startups for 'Spotlight' Program

XBIZ is pleased to announce that its new “Startup Spotlight” programming will make its European premiere at XBIZ Amsterdam 2025, set to take place Sept. 2-5 at the Jakarta Hotel Amsterdam.

Texas Resumes AV Lawsuit Against Aylo Following SCOTUS Decision

A district court judge in Texas has unfrozen the state’s $1.6 million lawsuit against Aylo for allegedly failing to comply with age verification requirements, Bloomberg Law is reporting.

JuicyAds Wins Trademark Infringement Case Against Fraudulent Domain

JuicyAds has won its World Intellectual Property Organization (WIPO) case against a website using a similar domain to impersonate the company's site and defraud customers.

Anissa Kate, Jordan Starr Top AEBN for Q2 of 2025

AEBN has published its top-selling stars for the second quarter of 2025, with Anissa Kate landing atop the leaderboard for straight theaters and Jordan Starr heading up the gay rankings.

Show More