{"id":226237,"date":"2010-01-25T12:20:53","date_gmt":"2010-01-25T17:20:53","guid":{"rendered":"http:\/\/www.stoth.com\/2010\/01\/25\/security-flaw-found-in-twitters-flash-widget\/"},"modified":"2010-01-25T12:20:53","modified_gmt":"2010-01-25T17:20:53","slug":"security-flaw-found-in-twitter%e2%80%99s-flash-widget","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/226237","title":{"rendered":"Security Flaw found in Twitter\u2019s Flash Widget"},"content":{"rendered":"<p><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/9fe1b_twitter-sul.jpg\">A recently discovered security flaw in Twitter&#8217;s Flash-based website widget may have allowed attackers access to the login credentials of any Twitter user. According to Mike Bailey, an analyst at<a href=\"http:\/\/foregroundsecurity.com\"> Foreground Security<\/a>, the problem involves a known vulnerability in Adobe&#8217;s Flash programming language, the language used to code the Twitter widget. In response, <a href=\"http:\/\/status.twitter.com\/post\/347863101\/flash-widget-disabled\">Twitter has disabled the widget in question<\/a> while they research the issue further. <\/p>\n<p align=\"right\"><em>Sponsor<\/em><br \/><a href=\"http:\/\/d.ads.readwriteweb.com\/ck.php?n=a6d5ead9&amp;cb=17939\" ><img src='http:\/\/d.ads.readwriteweb.com\/avw.php?zoneid=14&amp;cb=17939&amp;n=a6d5ead9' border='0' alt='' \/><\/a><\/p>\n<p>Oddly enough, the vulnerability in question was initially discovered back in 2006, but many website operators have yet to address it says Bailey, according to a <a href=\"http:\/\/uk.reuters.com\/article\/idUKN2213983720100122?rpc=401\">Reuters UK news story<\/a> about the potential Twitter security hole. After analyzing Twitter&#8217;s website, Bailey says the site may have been open to attack from hackers attempting to exploit this particular security hole for over a year. <\/p>\n<p>But the researcher doesn&#8217;t blame Adobe for the issue &#8211; the company informed programmers how to address the vulnerability years ago. Instead, this problem has to do with the &#8220;how the developers at Twitter, or whoever did this, built the Flash applications,&#8221; Bailey told a reporter at <a href=\"http:\/\/www.internetnews.com\/webcontent\/article.php\/3860311\">InternetNews.com<\/a>. <\/p>\n<p>According to <a href=\"http:\/\/status.twitter.com\/post\/347863101\/flash-widget-disabled\">a post<\/a> on the Twitter Status blog, the company has exercised &#8220;an abundance of caution&#8221; in disabling access to the widget as they have not yet heard about any accounts being affected by the reported vulnerability. However, says Bailey, there&#8217;s no way of know if any users were ever impacted by the issue and, if so, how many. &#8220;That is one of the big scary things; if they are being attacked, there is almost no way to find out short of a very close examination of the server logs or client logs, which generally aren&#8217;t stored,&#8221; <a href=\"http:\/\/www.internetnews.com\/webcontent\/article.php\/3860311\">he said<\/a>.<\/p>\n<p>This is by no means the first security issue for the microblogging startup. The company has seen everything from <a href=\"http:\/\/www.securityfocus.com\/brief\/1050\">DNS hijacking<\/a> to <a href=\"http:\/\/blog.searchenginewatch.com\/090717-001848\">the theft of corporate documents<\/a> and even fell victim to <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitter_facebook_and_livejournal_down_at_the_same.php\">a distributed denial-of-service attack<\/a> which affected other social media properties on the web including LiveJournal and Facebook. Twitter users have also had <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitter_security_collapses_oba.php\">their accounts hacked<\/a> and have had to deal with the <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitters_a_mess_first_the_ddos_now_koobface_returns.php\">constant threat of internet malware<\/a> posted to the site via shortened links. If anything, a news story about yet another Twitter security threat almost seems like a non-event these days, given how many issues the company has faced over the few short years they&#8217;ve been in operation. But considering current Twitter&#8217;s status as a piece of our modern-day&#8217;s communication infrastructure, it&#8217;s unnerving to hear about issues such as these&#8230;especially considering how this one in particular should have been addressed from the get-go. <\/p>\n<p><strong><a href=\"http:\/\/www.readwriteweb.com\/archives\/security_flaw_found_in_twitters_flash_widget.php#comments-open\">Discuss<\/a><\/strong><\/p>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/0\/da\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/9fe1b_di\" border=\"0\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/1\/da\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/f45f0_di\" border=\"0\"><\/img><\/a><\/p>\n<div>\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:FFnlKYwJmN0\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/f45f0_readwriteweb?d=FFnlKYwJmN0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:Ij26kaj3iuU\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/f45f0_readwriteweb?d=Ij26kaj3iuU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:C2pbw5bZMiI\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/70061_readwriteweb?d=C2pbw5bZMiI\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/70061_readwriteweb?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/70061_readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:V_sGLiPBpWU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/28041_readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:gIN9vFwOqvQ\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/28041_readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:F7zBnMyn0Lo\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:OqabYuBsmOY\"><img decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/28041_readwriteweb?d=OqabYuBsmOY\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.stoth.com\/wp-content\/plugins\/wp-o-matic\/cache\/28041_NQGP8UFxVJQ\" height=\"1\" width=\"1\" \/> <\/p>\n<p>Buy This Item: <a class=\"buy\" href=\"http:\/\/www.stoth.com\/buy.php\" ><span style=\"color: #33bc03\">[Click here to buy this item]<\/span><\/a><\/p>\n<p><a href=\"http:\/\/feedproxy.google.com\/~r\/readwriteweb\/~3\/NQGP8UFxVJQ\/security_flaw_found_in_twitters_flash_widget.php\" >Read Original Article<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recently discovered security flaw in Twitter&#8217;s Flash-based website widget may have allowed attackers access to the login credentials of any Twitter user. According to Mike Bailey, an analyst at Foreground Security, the problem involves a known vulnerability in Adobe&#8217;s Flash programming language, the language used to code the Twitter widget. In response, Twitter has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-226237","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/226237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=226237"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/226237\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=226237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=226237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=226237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}