Author Topic: YouTube open to cross site scripting!  (Read 3047 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
YouTube open to cross site scripting!
« on: December 25, 2006, 07:32:00 PM »
Hi malware fighters,

They warned us that it was only a matter of time before malware hackers could abuse YouTube. Here is the hole found to do this:
http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051451.html

While YouTube stays highly de-regulated, you better scan every link with DrWeb's before opening them up. Maicious code can only be turned into malware by starting it up (self-sought or automatically). So be aware while watching those video's. So it seems the regulators got some help from malcreants to get where they wanna go, and do not even go as far as to outlaw external linking (the end of the blog as we have known it probably!). Why the regulators and the de-regulators often seems to go hand in hand to achieve the goals that seems not desirable by us?

polonus


P.S. When you have the Netrcraft toolbar installed you are warned and protected against these infections through cross-site scripting!

D.
« Last Edit: December 25, 2006, 07:48:04 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: YouTube open to cross site scripting!
« Reply #1 on: December 28, 2006, 08:46:04 AM »
Was only a mter of time. Cant scan with the link checker on a mac but Ill install it on My Windows PC.
Thanks for the heads up
"People who are really serious about software should make their own hardware." - Alan Kay

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: YouTube open to cross site scripting!
« Reply #2 on: December 28, 2006, 11:11:56 AM »
Thanks polonus.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: YouTube open to cross site scripting!
« Reply #3 on: December 28, 2006, 02:57:34 PM »
Was only a mter of time. Cant scan with the link checker on a mac but Ill install it on My Windows PC.
Thanks for the heads up

You can bookmark this link and use that to manually check a link http://online.drweb.com/?url=1, paste the link you want to check into the entry window and click Scan, that should be it. You should be able to check it using your Mac browser and not have to switch OS just to check it out.
« Last Edit: December 28, 2006, 02:59:09 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: YouTube open to cross site scripting!
« Reply #4 on: December 28, 2006, 08:17:22 PM »
thanks
"People who are really serious about software should make their own hardware." - Alan Kay