Skip to main content

New Twitter security hole can expose direct messages

posted onOctober 5, 2010
by hitbsecnews

Twitter may be suffering from yet another embarrassing software security vulnerability, according to SearchEngineWatch.com. Apparently, if you use you Twitter credentials to log in to a third-party website, that site could gain access to your private direct messages. Gary-Adam Shannon, in a technical demonstration using WordPress and the Twitter API, shows how a small code change in the API code can send direct messages of logged in users directly to your email inbox of choice. Twitter has yet to comment on the vulnerability. For now, Shannon recommends not letting Twitter log you in to applications.

This vulnerability is the latest in a steady stream of embarrassing and crippling bugs in Twitter’s platform that seem to be popping up more and more often recently. As more visible vulnerabilities surface, more security pros will likely hop on the bandwagon to try and further exploit Twitter. This isn’t a bad thing, as the new attention being thrust on the software engineers at Twitter will (hopefully) make the service safer and more reliable in the future.

Source

Tags

Privacy

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th