YouTube hit with cross-site scripting vulnerability, Justin Bieber videos targeted

Security

youtube_logo-600

Sunday, users of Google’s video service YouTube were exposed to a cross-site scripting vulnerability that put the cookies of those visiting affected video pages at risk. Those employing the scripting vulnerability targeted videos of popular teen singer Justin Bieber, as some visitors saw: “tasteless messages pop up about the teen star, and were also redirected to external sites with adult content,” according to blog NetworkWorld. Google released a statement saying: “Comments were temporarily hidden by default within an hour, and we released a complete fix for the issue in about two hours. We’re continuing to study the vulnerability to help prevent similar issues in the future.” Google was also quick to point out that the compromised YouTube cookies did not provide unauthorized third-parties with access to users Google Accounts. Read

18 Comments
  • bgrfan

    And this is why you should use NoScript.

    • Virion

      Yes, NoScript FTW!

  • Justin Bieber

    I’m gay.

    • !

      Little lady, that would be a lesbian…

      • DaveNYC

        Scissoring

  • Justin Bieber

    I don’t know how to hold iPhones correctly!

  • lechero

    i spend all day watching tv and on the internet first time ive heard of this person. somehow i feel blessed.

  • fetus

    Anonymous is legion.

    • ~Phel

      Anon. is nowhere near where it was….

      • Anonymous

        It was those guys from ebaumsworld.

  • Swagger

    Still waiting on the EVO review….

    • SquareWheel

      There are plenty of reviews, why wait for a single site to review it?

  • Jazzyl

    That kid who sits alone at every lunch every day, eating his dessert.

  • Anonymous

    Serves them right for watching that midget’s videos.

  • RobertM

    Why does everyone act like Justin Bieber was the only target. Pretty much every featured video under every featured category was hit, as well as almost anyone that had over 25,000 subscribers.

  • DK

    Not Beaver, holy shit!!!!

  • An hero

    “the scripting vulnerability targeted videos of popular teen singer Justin Bieber”

    Don’t see anything wrong with this…

  • macewan

    that’s fate not a vulnerability

blog comments powered by Disqus