forum stepTV stepSTALKER sweatshop email Home

Go Back   The Drunken stepFORUM - A place to discuss your worthless opinions > General Discussion: > I am - Getting Drunk & Molesting You

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #8  
Old 07-05-2010, 11:55 AM
satan666
 

Posts: n/a
Credits: 0 [Check]
Default

Google acts to fix YouTube flaw exploited by hackers


YouTube has been forced to fix a flaw allowing hackers to bombard users
with fake pop-up messages and redirect them to adult sites.


Hackers placed code in the comments section, under targeted videos, that would run when people watched the clip.

In some cases, a pop-up screen appeared reporting that the Canadian singer, Justin Bieber, had died in a car crash.

Google, which owns YouTube, said that it had fixed the problem "about two hours" after it was discovered.

"We took swift action to fix a cross-site scripting (XSS) vulnerability on youtube.com," a spokesperson said.

"Comments were temporarily hidden by default within an hour, and we released a complete fix for the issue in about two hours.
Nasty attacks

Cross-site scripting (XSS) vulnerabilities are relatively simple attacks that allow hackers to place code into web pages.

In the YouTube incident, hackers used JavaScript code and HTML, both commonly used on web pages.

Security experts said that although in most cases the code was relatively benign, it has been used for more malicious purposes.

"The thing with a cross-site scripting attack is that it will appear that it is a message being posted by that website, which gives it a certain legitimacy, Graham Cluley of security firm Sophos told BBC News.

"It could be used to show a message that tells you to update your password; it could link to a malicious website; or it could attempt to phish you."

Phishing is a common tactic used by cybercriminals and involves using fake websites to lure people into revealing details such as bank accounts or login names.

"I've seen nasty XSS attacks that are used to fake whole login screens and we know how many people use same passwords for multiple accounts," said Bojan Zdrnja of the Internet Storm Centre in a blog post.

Mr Cluley said that responsibility for these kinds of vulnerabilites was down down to how securely a website was written.

"Web programmers need to be much more careful with their code."

Google said it was "continuing to study the vulnerability to help prevent similar issues in the future".

When the vulnerability was first reported, rumours suggested that YouTube was infected with a virus.


Code:
Content, Pictures  and Download links visible to registered users only. 

REGISTER NOW to access all areas that are invisible to non-members.
Reply With Quote
 


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:29 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
WE CANNOT POLICE EVERYTHING POSTED - IF YOU SEE YOUR COPYRIGHT MATERIAL - SEND US AN EMAIL AND WE WILL MAKE SURE TO REMOVE IT!Ad Management plugin by RedTyger