Members
  • Total Members: 12809
  • Latest: Dorel
Stats
  • Total Posts: 28477
  • Total Topics: 8238
  • Online Today: 797
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: YouTube Hacked by XSS vulnerability (ScreenShots)  (Read 5693 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
YouTube Hacked by XSS vulnerability (ScreenShots)
« on: 04. July 2010., 22:27:41 »


Malicious hackers attacked Google's YouTube on Sunday, exploiting a cross-site scripting (XSS) vulnerability on the ultra-popular video sharing site, hitting primarily sections where users post comments.

"Comments were temporarily hidden by default within an hour [of discovering the problem], and we released a complete fix for the issue in about two hours. We're continuing to study the vulnerability to help prevent similar issues in the future," a Google spokesman said via e-mail.

The attack potentially put at risk YouTube cookies of users who visited a compromised page, but it couldn't be used to access their Google accounts, the spokesman said. As a precaution, YouTube users should log out of their account and log back in again.

The attackers apparently targeted singer Justin Bieber, incorporating code into YouTube pages devoted to him so that visitors saw tasteless messages pop up about the teen star, and were also redirected to external sites with adult content.

An industry source familiar with the situation said that while the attack itself didn't involve malware infections, such a risk is inherent whenever users visit any Web page, such as the ones attackers redirected users to. It's not clear if those landing pages contained malware, but most up-to-date anti-virus software is designed to protect against those threats, this person said.

YouTube is by far the most popular video uploading and sharing site. In May, U.S. residents watched 14.6 billion video clips at Google sites, mostly at YouTube. which is about 43 percent of all clips watched online that month, according to comScore.

On a day when the U.S. marks its independence with fireworks shows, social media sites like Twitter and Facebook lit up on Sunday morning with reports from thousands of individuals who noticed the YouTube hack.

A separate stream of postings on social media sites focuses on whether Apple's iTunes App Store may have been compromised by a rogue developer and whether purchases may have been made without victims' permission using their credit cards on file.

People posting about the Apple issue are suggesting that App Store customers check for any unusual activity on their accounts.

Apple didn't immediately respond to a request for comment from IDG News Service.

(PCW)

Samker's Computer Forum - SCforum.info

YouTube Hacked by XSS vulnerability (ScreenShots)
« on: 04. July 2010., 22:27:41 »




Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #1 on: 04. July 2010., 22:46:04 »
ScreenShots:











*(to view them in full size, make a right button click with your mouse and choose "View Image", after that use back button in your browser... it's same for all Images at SCforum)



haz

  • SCF Advanced Member
  • ***
  • Posts: 117
  • KARMA: 26
  • Gender: Male
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #2 on: 05. July 2010., 07:35:05 »
So we are expecting something in 12/7 ? this is getting interesting :)
Thanks Samker

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #3 on: 05. July 2010., 13:23:27 »
So we are expecting something in 12/7 ?

Yes, it look like some Warning ???


Fireberg

  • SCF Advanced Member
  • ***
  • Posts: 163
  • KARMA: 21
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #4 on: 05. July 2010., 14:49:46 »
I love those guys...i´m mean, they really know what they doing...an all respct for googles engeniering of computers....waste millions and safety...and they can not do  anything about...just call the policy!!!

Thanx for keepying us info!!

Brian

  • SCF Member
  • **
  • Posts: 15
  • KARMA: 6
  • Gender: Male
  • We live in a digital world!
    • TechAirlines
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #5 on: 07. July 2010., 05:30:08 »
Thanks for the info!

Hmm "Expect us 7/12/2010" I wonder what they were planning...
Best regards,
Brian

TechAirlines - Journey into the World of Technology

bBbLaHhH

  • SCF Member
  • **
  • Posts: 42
  • KARMA: 6
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #6 on: 08. August 2010., 22:50:14 »
Any updates on this?  I'm interested to see what happened

would the date be July 12 or Dec 7th?

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #7 on: 09. August 2010., 05:57:48 »
Any updates on this?  I'm interested to see what happened

would the date be July 12 or Dec 7th?

YT simply "close" this "hole" in few hours...


Nothing, but Dec 7th is still possibility... ;)

vishwanath99

  • SCF Member
  • **
  • Posts: 61
  • KARMA: 6
  • Gender: Male
Re: YouTube Hacked by XSS vulnerability (ScreenShots)
« Reply #8 on: 11. August 2010., 10:53:24 »
THANKS

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising