Pinterest, StumbleUpon patch privacy flaws

By
Follow google news

Names, location and email addresses exposed.

Social networking sites Pinterest and StumbleUpon have patched vulnerabilities in their services that allowed attackers to discover user's personal information.

Pinterest, StumbleUpon patch privacy flaws

The flaws were found by security researcher Dan Melamed who detailed how a simple exploit could be run to potentially build a large email list for phishing attacks.

The Pinterest flaw worked by replacing a URL string with a username that returned a web page with a target’s email address.

"This flaw works with any user on Pinterest," Melamed said on a blog. "It works with either a username or a user ID. And it works with any access token."

StumbleUpon had patched a similar flaw in its service that exposed names, email address, location, age and gender, he said.

The disclosure follows widespread cracking of Pinterest accounts and an uptick in phishing scams targeting the network.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

USB stick opens Windows BitLocker drives in new zero-day

USB stick opens Windows BitLocker drives in new zero-day

'ClickFix' attack tricks users into hacking themselves, ACSC warns

'ClickFix' attack tricks users into hacking themselves, ACSC warns

Log In

  |  Forgot your password?