Posts tagged as:

backlink

Hackers Target YouTube With XXX XSS Attacks

by admin on Ιουλίου 7, 2010

Hackers hit YouTube over the weekend, injecting pop-ups, disabling comments and redirecting viewers to porn sites when they tried to access videos. Google (Nasdaq: GOOG) clamped down on the problem swiftly and is attempting to figure out who was behind the attack. The hack followed the online publication of a YouTube HTML code injection exploit. Dirty Deeds The hackers used a cross-site scripting (XSS) attack on YouTube. This is a technique that injects code into a user’s browser instance. A browser instance can be a standard browser client, a browser object embedded in a software product, an RSS reader or an email client. The attacking code is written in HTML, JavaScript, ActiveX, Flash or any other technology supported by browsers. In YouTube’s case, the attackers used HTML script on users’ comments pages. YouTube restricts the use of HTML in the comments section of its Web pages and uses a filter to ensure that any HTML used in comments doesn’t contain code. However, there is a flaw in this approach that was exploited by the hackers — using two script tags in a row lets people post any comments that include JavaScript code, according to a tweet en ) by Mikko Hypponen, F-Secure’s chief research officer. The YouTube filter will take out the first script tag but not the second. Some viewers who logged on to watch videos on YouTube were reportedly redirected to sites featuring adult entertainment as well as various shock sites around the Web. No Muss, Just Fuss News of the hack spread rapidly online, with some people speculating that YouTube had been hit by some sort of virus. However, the attack’s threat was limited, Google spokesperson Jay Nancarrow told TechNewsWorld. «This vulnerability allowed attackers to insert their own HTML code into certain YouTube pages,» Nancarrow explained. «It could not have been used to access any Google accounts or other properties.» The attack was «more of an annoyance than a threat,» Nancarrow said. Google temporarily hid comments by default within one hour of learning about the hack and released a complete fix for the problem within two hours, Nancarrow said. It’s continuing to study the vulnerability to help prevent similar issues in the future. Nancarrow declined to comment on reports that videos of teen singer Justin Bieber were the most heavily hacked. So, Whodunit? Some reports claim the hackers were users of the 4Chan Internet subculture and activism website. However, Nancarrow refused to speculate about the identity of the hackers. «Google is fully investigating the issue,» Nancarrow remarked. The attack followed the posting of information about the HTML vulnerability in YouTube by «TinKode» on a Romanian blog July 3. The writer gave examples of how to activate HTML in comments, how to launch popups, and how to redirect YouTube viewers to other sites. «TinKode» also posted proof of the HTML injection exploit detailed in the blogpost. Posting the exploit on the Internet was not a wise move, Randy Abrams, director of technical education at ESET, told TechNewsWorld. «TinKode needs a skilled mentor because he is not at all good at responsible disclosure,» Abrams remarked. Generally, responsible disclosure involves privately informing the site in question about the vulnerability, then giving it adequate time to fix the problem before publicizing it. Fending Off XSS Attacks Although Google shut down the attack on YouTube, it may still be vulnerable to XSS attacks, as are other websites, ESET’s Abrams warned. «Preventing XSS attacks requires a lot of code review and, generally, outside consultants to help,» Abrams explained. «Even then, it’s not guaranteed that all potential attacks have been identified.» That’s because XSS attacks come in many forms. There are three basic types of XSS attacks: Non-persistent, persistent and DOM-based. DOM, the Document Object Model, is a cross-platform and language-independent convention for representing and interacting with objects in HTML, XHTML and XML documents. In non-persistent attacks and DOM attacks, victims have to either visit a link seeded with malicious code or visit a malicious Web page containing a form that will unleash the attack. Such Web forms can be submitted automatically without the victim’s knowledge. In persistent attacks, the attacker stores malicious code on a website for some time. Victims don’t have to do anything to trigger an attack; they just have to view the page containing the code. «If we knew of all the ways these attacks can be carried, the top sites would prevent all of them,» Abrams said. «However, there are probably more undiscovered or undisclosed tricks out there. Additionally, the implementation of new technologies or even new versions of current software will undoubtedly produce new opportunities for all kinds of exploitation

Source: http://www.technewsworld.com/story/Hackers-Target-YouTube-With-XXX-XSS-Attacks-70357.html

Metamarks

{ 0 comments }

Google gets license to operate in China

Ιουλίου 2, 2010

SHANGHAI (Reuters) – Web services leader Google Inc. (GOOG.O: Quote, Profile, Research) has won a license to operate in China and has bought a Web address as it battles Yahoo Inc. (YHOO.O: Quote, Profile, Research) in the world’s second-largest Internet market. The U.S. Web services giant, which makes its money from searches, advertising and other [...]

More seo Telia.co.gr ---->

Reciprocal Links … again

Ιουλίου 2, 2010

 Reciprocal Links … again As they mentioned over on SE Round Table – the discussion regarding reciprocal links has been had hundreds – and maybe even thousands of times. At least once per week I get asked about them either whether they’re part of what we do or if te person on the phone should [...]

More seo Telia.co.gr ---->

Why should I care about Social Media Marketing?

Μαρτίου 22, 2010

The rise of social networks, blogs, wikis, social bookmarking and other Web 2.0 tools has created a new dynamic source of traffic for your website or any other online profile you might have. A top article on Digg can drive much more traffic to your website and blog than a top search engine ranking could [...]

More seo Telia.co.gr ---->

SEO: DIYS (Do it your self)!

Μαΐου 27, 2009

SEO….μια μεγάλη κουβέντα και ακόμα μεγαλύτερη τα  βήματα τα οποία πρέπει να ακολουθήσουμε για να έχουμε αποτελέσματα. Μαζέψαμε για σας ένα γρήγορο SEO Checklist ώστε να έχουμε μια βάση για να αρχίσουμε. Ωστόσο η διαδικασία για το SEO είναι χρονοβόρα και απαιτεί πολύ προσωπικό χρόνο απο μας….
Μοιράσου το με:

More seo Telia.co.gr ---->