05 Jul 2010
YouTube users have reacted angrily to a cross-site scripting exploit that hid comments on videos this weekend.
The problems appeared to begin on videos relating to teen pop sensation Justin Bieber, but soon began to spread to other videos, according to reports.
The infections do not appear to have a dangerous payload, but have annoyed users who expressed their opinions on the YouTube help forums.
"Where are the YouTube moderators to answer this? I think it's affecting thousands of people. You can also block such users as soon as one of your videos get infected, otherwise they will continue to damage your other ones too!" said one user.
"They need to really step security up, never realised until now how many security loopholes there is," added another.
Security firm Sunbelt Software warned that the implications could have been much worse if the same exploit had been carried out by a more malicious group.
"If this exploit had been discovered by a professional money-making outfit, there could have been all sorts of subtle attacks taking place for a long time. Not good, given the apparent simplicity of the attack," said Christopher Boyd, senior threat researcher at the vendor, in a blog post.
YouTube acknowledged the scripting bug in an official response, and promised that it has removed the risk of another attack.
"We took swift action to fix a cross-site scripting vulnerability on youtube.com that was discovered several hours ago," said a spokesman.
"Comments were temporarily hidden by default within an hour, and we released a complete fix for the issue in about two hours. We're continuing to study the vulnerability to help prevent similar issues in the future."
The spokesman added that, contrary to some reports, the issue could not have been used to gain access to a victim's Google account.
Latest stories from Software
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Project Manager, London - Software Solutions (Project...
Project Manager - Hampshire - up to £32K - Fixed Term...
Senior Customer Support Consultant - 2nd/3rd Line Support...
C++/C#/Java developer for a global investment bank within...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
No credit for security researcher who discovered this flaw?
I have read news from many sources about this security issue, but no one credited TinKode from Romanian Insecurity Team who discovered it first and published details and a proof-of-concept on his blog on 3rd of July (http://blog.insecurity.ro/youtube-html-code-injection/)
Posted by: D1M 05 Jul 2010