Monday, March 02, 2015
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Crafted from Metal and Glass, Samsung Galaxy S6 and Galaxy S6 Edge Are Here
MWC: SanDisk Introduces New Mobile Flash Drives, iNAND 7132 Storage Solution And 200GB microSDXC Card
MWC: New Tablets By Lenovo
Firefox OS Expands with More Partners, Devices
MWC: MediaTek Releases SoCs For Smartphones And Tablets
HP Introduces The Spectre x360 Convertible PC
Acer Unveils Windows Phone 10-ready smartphone At MWC
New ZTE Grand S3 Smartphone Offers EyeVerify Authentication
Active Discussions
Need serious help!!!!
burning
nvidia 6200 review
Hello
Burning Multimedia in track 0
I'm lazy. Please help.
sanyo e6 camera
need help on some cd burning...
 Home > News > General Computing > Youtube...
Last 7 Days News : SU MO TU WE TH FR SA All News

Monday, July 05, 2010
Youtube Hit By Code Injection Attack


YouTube was hit by a persistent cross-site scripting (XSS) vulnerability which affects YouTube's comment field.

Malicious JavaScript was inserted into user's comments by exploiting a XSS flaw. The bug was abused by unnamed attackers to poison the comments on multiple videos.

Researchers from a Romanian security team (InSecurityRomania) have revealed the vulnerability first.

Google has corrected the issue now but it is possible that malicious users have already exploited it to redirect unwitting YouTube users watching videos to drive-by download pages in order to infect them with malware, adware and spyware.

Cross-site scripting (XSS) vulnerabilities is a type of computer security vulnerability typically found in web applications that enables malicious attackers to inject client-side script into web pages viewed by other users.

Experts distinguish between at least two primary flavors of XSS: non-persistent and persistent.

The non-persistent (or reflected) cross-site scripting vulnerability is by far the most common type. For example, a non-persistent XSS vulnerabilitie in Google could allow malicious sites to attack Google users who visit them while logged in.

The persistent XSS vulnerability is a more devastating variant of a cross-site scripting flaw: it occurs when the data provided by the attacker is saved by the server, and then permanently displayed on "normal" pages returned to other users in the course of regular browsing, without proper HTML escaping. For example, a persistent cross-zone scripting vulnerability coupled with a computer worm allowed execution of arbitrary code and listing of filesystem contents via a QuickTime movie on MySpace.


Previous
Next
Sony Introduces Slim PS3 in Japan        All News        E-books Still Slower Than Reading Print, Study Says
Bluetooth Opens Qualification Program For Bluetooth Version 4.0 Devices     General Computing News      IBM is Moving to Firefox As Its Default Browser

Get RSS feed Easy Print E-Mail this Message

Related News
YouTube To Release Kids App
Google Launches Chinese Language Developer Channel on YouTube
Researchers Identify iOS Espionage App
YouTube Now Defaults to HTML5
YouTube Lets You Create Animated GIFs
Youtube Introduces Paid Music Service
Researchers Identify New iOS Vulnerability
RTL To Control YouTube Fashion Platform
YouTube Now Supports 60fps Videos
YouTube To Launch Paid Video Service
YouTube To Fund Hollywood Content Creation: report
Youtube Rates ISP's Video Atreaming Quality

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2015 - All rights reserved -
Privacy policy - Contact Us .