{"id":227291,"date":"2010-01-25T11:31:32","date_gmt":"2010-01-25T16:31:32","guid":{"rendered":"http:\/\/www.readwriteweb.com\/archives\/security_flaw_found_in_twitters_flash_widget.php"},"modified":"2010-01-25T11:31:32","modified_gmt":"2010-01-25T16:31:32","slug":"security-flaw-found-in-twitters-flash-widget","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/227291","title":{"rendered":"Security Flaw found in Twitter&#8217;s Flash Widget"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.readwriteweb.com\/twitter-sul.jpg\">A recently discovered security flaw in Twitter&#8217;s Flash-based website widget may have allowed attackers access to the login credentials of any Twitter user. According to Mike Bailey, an analyst at<a href=\"http:\/\/foregroundsecurity.com\"> Foreground Security<\/a>, the problem involves a known vulnerability in Adobe&#8217;s Flash programming language, the language used to code the Twitter widget. In response, <a href=\"http:\/\/status.twitter.com\/post\/347863101\/flash-widget-disabled\">Twitter has disabled the widget in question<\/a> while they research the issue further. <\/p>\n<p align=\"right\"><em>Sponsor<\/em><br \/><a href='http:\/\/d.ads.readwriteweb.com\/ck.php?n=a6d5ead9&amp;cb=17939' ><img src='http:\/\/d.ads.readwriteweb.com\/avw.php?zoneid=14&amp;cb=17939&amp;n=a6d5ead9' border='0' alt='' \/><\/a><\/p>\n<p>Oddly enough, the vulnerability in question was initially discovered back in 2006, but many website operators have yet to address it says Bailey, according to a <a href=\"http:\/\/uk.reuters.com\/article\/idUKN2213983720100122?rpc=401\">Reuters UK news story<\/a> about the potential Twitter security hole. After analyzing Twitter&#8217;s website, Bailey says the site may have been open to attack from hackers attempting to exploit this particular security hole for over a year. <\/p>\n<p>But the researcher doesn&#8217;t blame Adobe for the issue &#8211; the company informed programmers how to address the vulnerability years ago. Instead, this problem has to do with the &#8220;how the developers at Twitter, or whoever did this, built the Flash applications,&#8221; Bailey told a reporter at <a href=\"http:\/\/www.internetnews.com\/webcontent\/article.php\/3860311\">InternetNews.com<\/a>. <\/p>\n<p>According to <a href=\"http:\/\/status.twitter.com\/post\/347863101\/flash-widget-disabled\">a post<\/a> on the Twitter Status blog, the company has exercised &#8220;an abundance of caution&#8221; in disabling access to the widget as they have not yet heard about any accounts being affected by the reported vulnerability. However, says Bailey, there&#8217;s no way of know if any users were ever impacted by the issue and, if so, how many. &#8220;That is one of the big scary things; if they are being attacked, there is almost no way to find out short of a very close examination of the server logs or client logs, which generally aren&#8217;t stored,&#8221; <a href=\"http:\/\/www.internetnews.com\/webcontent\/article.php\/3860311\">he said<\/a>.<\/p>\n<p>This is by no means the first security issue for the microblogging startup. The company has seen everything from <a href=\"http:\/\/www.securityfocus.com\/brief\/1050\">DNS hijacking<\/a> to <a href=\"http:\/\/blog.searchenginewatch.com\/090717-001848\">the theft of corporate documents<\/a> and even fell victim to <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitter_facebook_and_livejournal_down_at_the_same.php\">a distributed denial-of-service attack<\/a> which affected other social media properties on the web including LiveJournal and Facebook. Twitter users have also had <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitter_security_collapses_oba.php\">their accounts hacked<\/a> and have had to deal with the <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitters_a_mess_first_the_ddos_now_koobface_returns.php\">constant threat of internet malware<\/a> posted to the site via shortened links. If anything, a news story about yet another Twitter security threat almost seems like a non-event these days, given how many issues the company has faced over the few short years they&#8217;ve been in operation. But considering current Twitter&#8217;s status as a piece of our modern-day&#8217;s communication infrastructure, it&#8217;s unnerving to hear about issues such as these&#8230;especially considering how this one in particular should have been addressed from the get-go. <\/p>\n<p><strong><a href=\"http:\/\/www.readwriteweb.com\/archives\/security_flaw_found_in_twitters_flash_widget.php#comments-open\">Discuss<\/a><\/strong><\/p>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~at\/jpmWoCtox6leWnq7CpNai-5yAS8\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:FFnlKYwJmN0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?d=FFnlKYwJmN0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:Ij26kaj3iuU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?d=Ij26kaj3iuU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:C2pbw5bZMiI\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?d=C2pbw5bZMiI\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:V_sGLiPBpWU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:gIN9vFwOqvQ\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?i=NQGP8UFxVJQ:TTyRhtFQ-dA:F7zBnMyn0Lo\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?a=NQGP8UFxVJQ:TTyRhtFQ-dA:OqabYuBsmOY\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/readwriteweb?d=OqabYuBsmOY\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/readwriteweb\/~4\/NQGP8UFxVJQ\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recently discovered security flaw in Twitter&#8217;s Flash-based website widget may have allowed attackers access to the login credentials of any Twitter user. According to Mike Bailey, an analyst at Foreground Security, the problem involves a known vulnerability in Adobe&#8217;s Flash programming language, the language used to code the Twitter widget. In response, Twitter has [&hellip;]<\/p>\n","protected":false},"author":2952,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-227291","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/227291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/2952"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=227291"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/227291\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=227291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=227291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=227291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}