YouTube has been forced to fix a flaw allowing hackers to bombard users with fake pop-up messages and redirect them to adult sites. Hackers placed code in the comments section, under targeted videos, that would run when people watched the clip.
In some cases, a pop-up screen appeared reporting that the Canadian singer, Justin Bieber, had died in a car crash. Google, which owns YouTube, said that it had fixed the problem "about two hours" after it was discovered.
Cross-site scripting (XSS) vulnerabilities are relatively simple attacks that allow hackers to place code into web pages. In the YouTube incident, hackers used JavaScript code and HTML, both commonly used on web pages.
Security experts said that although in most cases the code was relatively benign, it has been used for more malicious purposes. Phishing is a common tactic used by cyber criminals and involves using fake websites to lure people into revealing details such as bank accounts or login names.
Google said it was "continuing to study the vulnerability to help prevent similar issues in the future". When the vulnerability was first reported, rumors suggested that YouTube was infected with a virus.
No comments:
Post a Comment