Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Aylo Willing to Work With Australia's Online Censor on Device-Based AV Solutions

The office of Australia’s top online censor, unelected eSafety Commissioner Julie Inman Grant, released a new roadmap for implementing age verification according to the country’s Online Safety Act.

Spain's Technology Minister Unveils Soon-to-be-Mandatory Age Verification App

Spain’s anti-sex work and anti-porn Socialist Party (PSOE) government led by Prime Minister Pedro Sánchez unveiled a new age verification app that will become a mandatory step to access any adult content by anyone in the country starting in September.

FSC Drops Opposition to California Age Verification Bill After Amendments

Free Speech Coalition (FSC) has dropped its formal opposition to California’s age verification bill AB 3080, after an amendment secured through months of discussions with the bill’s author was heard by the Senate Judiciary Committee.

SCOTUS Agrees to Hear Texas Age Verification Challenge

The United States Supreme Court granted on Tuesday the petition for a writ of certiorari in the Free Speech Coalition-led challenge to Texas’ age verification law, agreeing to hear the case in the next term.

Dorcel Group Acquires LifeSelector

Dorcel Group has acquired interactive content company LifeSelector.

Etsy Updates Policy to Ban Sale of Most Adult Pleasure Products, Content

Etsy will ban sales of most pleasure products and content that depicts sex acts and genitalia starting July 29.

Jamie Page Is LoyalFans' 'Featured Creator' for July

LoyalFans has named Jamie Page as its Featured Creator for July.

Byborg's Le Shaw Research Institute Teams Up With SWOP Behind Bars

LiveJasmin parent company Byborg Enterprises’ Le Shaw International Sexual Health and Wellness Research Institute has joined forces with U.S.-based sex worker advocacy group SWOP Behind Bars.

AI Erotic Storytelling Platform 'Erota' Launches

Erota, a new AI-powered erotic storytelling platform, has debuted.

Indiana Court Blocks Age Verification Law

A U.S. district court in Indiana has blocked the state's age verification law from taking effect this coming Monday, July 1.

Show More