Youtube vulnerability

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • AndyD
    Diamond Member

    • Jan 2010
    • 4946

    #1

    Youtube vulnerability

    There's a YouTube commenting bug that allows anyone to easily inject redirects/code/... into any comment. The script kiddies at 4Chan are already exploiting it in an attack on Justin Bieber videos, but there are many harmful redirects as well.

    It would be possible to become a victim of this type of attack from a youtube link on boards such as this one so best avoid everything 'youtube' till they sort out their sloppy code.

    Apparently YouTube can't fix it quickly so they've turned off their commenting system for now.
    _______________________________________________

    _______________________________________________
  • Dave A
    Site Caretaker

    • May 2006
    • 22812

    #2
    Originally posted by AndyD
    There's a YouTube commenting bug that allows anyone to easily inject redirects/code/... into any comment.

    ...

    It would be possible to become a victim of this type of attack from a youtube link on boards such as this one so best avoid everything 'youtube' till they sort out their sloppy code.
    As far as I know, the embedded media script we use here only pulls the video and title...
    Participation is voluntary.

    Alcocks Electrical Services | Alcocks Pest Control & Entomological Services | Alcocks Hygiene Services

    Comment

    • AndyD
      Diamond Member

      • Jan 2010
      • 4946

      #3
      I just thought it was worth a warning, I'm not sure if the parsing of links presents a problem, if I read anything I'll let you know. With the kind of resources they have, I'm sure they'll sort it out soon....maybe they should just dump all the Justin Beiber videos and do the world a favour at the same time
      _______________________________________________

      _______________________________________________

      Comment

      Working...