phpBB Forum
 
It is currently Wed Mar 25, 2020 4:07 pm




Post new topic Reply to topic  [ 7 posts ] 
Avoid YouTUBE - Security Issue. 
Author Message
HH Donor
HH Donor
User avatar

Joined: Tue Dec 25, 2007 12:08 am
Posts: 6095
STEAM_0:0:16743808
MCID: frog
Post Avoid YouTUBE - Security Issue.
Avoid visiting YouTUBE for the time being. There is a comments exploit that is rampant at the moment. It allows anyone to inject arbitrary code into any YouTUBE video page.

It is being used for all kinds of things, including cookie stealing, redirection to malicious payloads, IE vulnerabilities, etc, and it is spreading like wildfire.

Google will be able to fix it easily and track whoever has injected harmful code, but in the mean time for your own security avoid visiting YouTUBE.


Sun Jul 04, 2010 2:39 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun Feb 15, 2009 9:23 pm
Posts: 4908
Location: Aruba
STEAM_0:1:11237970
MCID: pgt
Post Re: Avoid YouTUBE - Security Issue.
thanks for the info !
seen some code pieces online, god i hate those people ...

_________________


Sun Jul 04, 2010 2:45 pm
Profile E-mail
@H|H Reg
@H|H Reg
User avatar

Joined: Sat Aug 15, 2009 5:02 am
Posts: 1460
Location: West Yorkshire
STEAM_0:1:5427557
MCID: JamsteRx
Post Re: Avoid YouTUBE - Security Issue.
I know i just saw it said disable comments for security reasons :oops:

_________________
Hi


Sun Jul 04, 2010 3:42 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Tue Dec 25, 2007 12:08 am
Posts: 6095
STEAM_0:0:16743808
MCID: frog
Post Re: Avoid YouTUBE - Security Issue.
It's been patched and cleaned now.


Sun Jul 04, 2010 3:58 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Tue Dec 25, 2007 12:08 am
Posts: 6095
STEAM_0:0:16743808
MCID: frog
Post Re: Avoid YouTUBE - Security Issue.
In case anyone was wondering what happened, here is a link that explains http://blog.insecurity.ro/youtube-html-code-injection/


Sun Jul 04, 2010 4:46 pm
Profile E-mail
HH Member
HH Member
User avatar

Joined: Thu Mar 13, 2008 12:49 am
Posts: 1374
Location: Warwickshire
STEAM_0:0:11320859
MCID: TRIUMVIRATE
Post Re: Avoid YouTUBE - Security Issue.
frog wrote:
In case anyone was wondering what happened, here is a link that explains http://blog.insecurity.ro/youtube-html-code-injection/

Thanks for the link, I've seen this a lot on minor sites to great effect (embedding hilarious songs on news links for instance) but never on something as collossal as youtube.

_________________
They took from their surroundings what was needed, and made of it something more.


Sun Jul 04, 2010 4:50 pm
Profile E-mail
@H|H Reg
@H|H Reg
User avatar

Joined: Sat Dec 19, 2009 5:54 pm
Posts: 1471
Location: Romania
STEAM_0:0:26083532
MCID: x_elx
Post Re: Avoid YouTUBE - Security Issue.
I love how the Romanians explain it :)

_________________
Deepblue wrote:
It also lets you see someone's head if they're going to hit you from behind.


WINNER OF 2010's BAD SEED CATEGORY
SECOND PLACE IN THE CHATTERBOX CATEGORY OF 2010
THIRD OR SECOND PLACE IN THE UNSTABLE ISOTOPE CATEGORY OF 2010


Sun Jul 04, 2010 10:23 pm
Profile E-mail
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © phpBB Group.
Designed by Vjacheslav Trushkin for Free Forum/DivisionCore.