Results 1 to 3 of 3

Thread: Youtube vulnerability

  1. #1
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,400
    Thanks
    513
    Thanked 854 Times in 687 Posts

    Youtube vulnerability

    There's a YouTube commenting bug that allows anyone to easily inject redirects/code/... into any comment. The script kiddies at 4Chan are already exploiting it in an attack on Justin Bieber videos, but there are many harmful redirects as well.

    It would be possible to become a victim of this type of attack from a youtube link on boards such as this one so best avoid everything 'youtube' till they sort out their sloppy code.

    Apparently YouTube can't fix it quickly so they've turned off their commenting system for now.

  2. #2
    Site Caretaker Dave A's Avatar
    Join Date
    May 2006
    Location
    Durban, South Africa
    Posts
    20,977
    Thanks
    3,055
    Thanked 2,462 Times in 2,067 Posts
    Blog Entries
    12
    Quote Originally Posted by AndyD View Post
    There's a YouTube commenting bug that allows anyone to easily inject redirects/code/... into any comment.

    ...

    It would be possible to become a victim of this type of attack from a youtube link on boards such as this one so best avoid everything 'youtube' till they sort out their sloppy code.
    As far as I know, the embedded media script we use here only pulls the video and title...
    The trouble with opportunity is it normally comes dressed up as work.

  3. #3
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,400
    Thanks
    513
    Thanked 854 Times in 687 Posts
    I just thought it was worth a warning, I'm not sure if the parsing of links presents a problem, if I read anything I'll let you know. With the kind of resources they have, I'm sure they'll sort it out soon....maybe they should just dump all the Justin Beiber videos and do the world a favour at the same time

Similar Threads

  1. For YouTube Users
    By tec0 in forum Technology Forum
    Replies: 11
    Last Post: 27-May-10, 09:29 AM
  2. Using youtube
    By Dave A in forum Business Online Forum
    Replies: 11
    Last Post: 05-Jun-09, 04:43 PM
  3. Youtube??
    By Ryan S in forum Marketing Forum
    Replies: 4
    Last Post: 03-Aug-08, 03:19 PM
  4. Testing youtube
    By SilverNodashi in forum Administrative issues
    Replies: 1
    Last Post: 25-May-08, 07:31 PM
  5. YouTube slapped with billion-dollar lawsuit
    By Dave A in forum General Business Forum
    Replies: 0
    Last Post: 13-Mar-07, 09:16 PM

Did you like this article? Share it with your favourite social network.

Did you like this article? Share it with your favourite social network.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •