Myspace lets anyone view private profiles

On August 18 2006 a post was made at our website explaining how easy it was to access (private) comments and photos on Myspace profiles set to "private". This vulnerability in Myspace profiles had apparently been known by the "Myspace underground" for some time, but had not been addressed by the Myspace security people. On August 26, this vulnerability was made public on and suddenly the whole world knew about it. Once in the spotlight, Myspace band-aided this "view private profile" hole in less than 24 hours.

Note: The information contained on this page is for educational purposes only. It is hoped that by making such breaches in Myspace privacy/security public, Myspace administrators/programmers can correct the issue and prevent further lapses in security in the future. has been notified of this security vulnerability. Originally posted: 8/18/06; 12:05PM

Posted by: xxrachelnic0lexx;

Subject: comments on a private profile's the Myspace code to view private comments: *insert their Myspace friendID at the end For pictures: ** **Put the friendID there


It seems that even if a profile has been deleted, MySpace still retain all private images associated with the account. Hence if you look up a userid of a deleted user, it is simply identified as "Friend", and if you follow that link you will get the message that the account has been deleted.

I doubt anything was actually fixed. You can still view pictures if you happen to know the exact URL. Can't do a safe mode edit on your own comments either. The code is just absent from the .cfm files now. If anyone has cached copies of and, I bet they will still work.

