Tumblr Users Should Beware of Cookie Thieves

Two researchers say they’ve found a security hole in Tumblr, one of the most popular sites on the Internet, that could steal users’ authentication cookies to break into their accounts.

Aditya Gupta and Subho Halder say they’ve tried to contact Tumblr about the vulnerability by using mail and Twitter, but so far no one has responded. The social sharing site hosts 59.4 million micro blogs and has published almost 25 billion posts.

The pair says they have identified a dangerous cross-site scripting vulnerability that poses risks for the site’s users, according to the site Softpedia.

“I could get the cookies of any user who visits my profile page. They are the actual Tumblr authentication cookies, which means I could use the cookies to log in to the respective user accounts,” Gupta said. “Also, I could make a complete worm out of it, so when one person views my profile, he would repost my post and everyone in his list who would see it would then be doing the same. All automatically and without the user’s knowledge.”

via Threatpost

Notes

  1. nursegeorgie reblogged this from charethcutestory
  2. wolfbird reblogged this from infoneer-pulse
  3. tanya77 reblogged this from winstonwolfe and added:
    “Aditya Gupta and Subho Halder say they’ve tried to contact Tumblr about the vulnerability by using mail and Twitter,...
  4. leoyardiechick reblogged this from witchsistah
  5. somedeadbody reblogged this from sunnylust
  6. alectointhunderland reblogged this from ro-s-aspa-rks
  7. mosteeze reblogged this from war-horse-can-dance
  8. war-horse-can-dance reblogged this from arrestomomentum
  9. knope4president reblogged this from charethcutestory
  10. arrestomomentum reblogged this from dayhyungs
  11. raakkel reblogged this from applebutterbomb
  12. theprinceisgone reblogged this from afternoondlite
  13. sunnylust reblogged this from taozitao
  14. jennjenn202 reblogged this from babojae
  15. misakichiuaua reblogged this from taozitao
  16. angelsscream reblogged this from witchsistah
  17. witchsistah reblogged this from deliciouskaek
  18. feedmyobsessions reblogged this from curtainwitcharchive
  19. yabamena reblogged this from saltmarsh and added:
    Gee, someone points out something wrong with Tumblr and Tumblr staff does nothing? I’m shocked. Shocked, I say.
  20. saltmarsh reblogged this from infoneer-pulse and added:
    How concerned should we be about this?
  21. waaaahlbodayz reblogged this from itnww
  22. afternoondlite reblogged this from jong-in-becca
  23. jong-in-becca reblogged this from yunheaux
  24. godric reblogged this from curtainwitcharchive
  25. scoldylox reblogged this from glossylalia and added:
    Um.
  26. babojae reblogged this from taozitao
  27. yushiny reblogged this from taozitao