Samker's Computer Forum - SCforum.info

World TOP Headlines: => Latest Security News & Alerts => Topic started by: Samker on 04. July 2010., 22:27:41

Title: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Samker on 04. July 2010., 22:27:41
(http://showclix.com/blog/wp-content/uploads/2009/04/youtube-logo.jpg)

Malicious hackers attacked Google's YouTube on Sunday, exploiting a cross-site scripting (XSS) vulnerability on the ultra-popular video sharing site, hitting primarily sections where users post comments.

"Comments were temporarily hidden by default within an hour [of discovering the problem], and we released a complete fix for the issue in about two hours. We're continuing to study the vulnerability to help prevent similar issues in the future," a Google spokesman said via e-mail.

The attack potentially put at risk YouTube cookies of users who visited a compromised page, but it couldn't be used to access their Google accounts, the spokesman said. As a precaution, YouTube users should log out of their account and log back in again.

The attackers apparently targeted singer Justin Bieber, incorporating code into YouTube pages devoted to him so that visitors saw tasteless messages pop up about the teen star, and were also redirected to external sites with adult content.

An industry source familiar with the situation said that while the attack itself didn't involve malware infections, such a risk is inherent whenever users visit any Web page, such as the ones attackers redirected users to. It's not clear if those landing pages contained malware, but most up-to-date anti-virus software is designed to protect against those threats, this person said.

YouTube is by far the most popular video uploading and sharing site. In May, U.S. residents watched 14.6 billion video clips at Google sites, mostly at YouTube. which is about 43 percent of all clips watched online that month, according to comScore.

On a day when the U.S. marks its independence with fireworks shows, social media sites like Twitter and Facebook lit up on Sunday morning with reports from thousands of individuals who noticed the YouTube hack.

A separate stream of postings on social media sites focuses on whether Apple's iTunes App Store may have been compromised by a rogue developer and whether purchases may have been made without victims' permission using their credit cards on file.

People posting about the Apple issue are suggesting that App Store customers check for any unusual activity on their accounts.

Apple didn't immediately respond to a request for comment from IDG News Service.

(PCW)
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Samker on 04. July 2010., 22:46:04
ScreenShots:


(http://i50.tinypic.com/30xizag.jpg)


(http://img687.imageshack.us/img687/6482/yt3.png)


(http://img822.imageshack.us/img822/6633/40125229.png)


*(to view them in full size, make a right button click with your mouse and choose "View Image", after that use back button in your browser... it's same for all Images at SCforum)


Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: haz on 05. July 2010., 07:35:05
So we are expecting something in 12/7 ? this is getting interesting :)
Thanks Samker
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Samker on 05. July 2010., 13:23:27
So we are expecting something in 12/7 ?

Yes, it look like some Warning ???

Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Fireberg on 05. July 2010., 14:49:46
I love those guys...i´m mean, they really know what they doing...an all respct for googles engeniering of computers....waste millions and safety...and they can not do  anything about...just call the policy!!!

Thanx for keepying us info!!
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Brian on 07. July 2010., 05:30:08
Thanks for the info!

Hmm "Expect us 7/12/2010" I wonder what they were planning...
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: bBbLaHhH on 08. August 2010., 22:50:14
Any updates on this?  I'm interested to see what happened

would the date be July 12 or Dec 7th?
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: Samker on 09. August 2010., 05:57:48
Any updates on this?  I'm interested to see what happened

would the date be July 12 or Dec 7th?

YT simply "close" this "hole" in few hours...


Nothing, but Dec 7th is still possibility... ;)
Title: Re: YouTube Hacked by XSS vulnerability (ScreenShots)
Post by: vishwanath99 on 11. August 2010., 10:53:24
THANKS