Myspace may sound like a distant and forgotten thing, but there was a time when it was the most in and millions of users had their own personal accounts. Many of those accounts are still active and quite vulnerable to hackingdue to a bug that the company has neglected to fix.

Security researcher Leigh-Anne Galloway discovered a vulnerability in Myspace that allows anyone to hack into an account without knowing the password, account holder name, username, email, and date of birth. Essentially, these are the only pieces of information the service requires.
All of this information can be found online, with the user's first and last name even appearing on each account's Myspace page. Of course, the email can be found online with a little more research.
The worst part is that the researcher has been warning about this specific vulnerability since April of this year, but the service ignored the warning, thus leaving accounts at the mercy of hackers.
After almost three months, and specifically a few days ago, Myspace finally decided to address the vulnerability, but instead of releasing a patch , it decided to completely remove the account recovery page.
"How important is security to Myspace? I sent an email to the service in April reporting the vulnerability but no one took action. I had to disclose the vulnerability in case I upset them. But it seems that the service doesn't really care about the fate of your accounts. So if anyone still has a Myspace account, it would be a good idea to delete it immediately," said Leigh-Anne Galloway.
Since there aren't many people using Myspace anymore, the vulnerability doesn't seem that significant, but a potential breach could prove devastating if users' credentials are used on other accounts.
