ghacks Technology News

Google fixes YouTube xxx spam flaw

YouTube owner Google has been forced to act quickly to fix a flaw on it’s YouTube video sharing website that allowed hackers to bombard users with pop-up messages, redirecting them to adult websites.

The code was placed in the comments section of targeted videos and would run automatically when people watched the clip.

Google says the problem was fixed within only two hours of being reported, according to the BBC.

“We took swift action to fix a cross-site scripting (XSS) vulnerability on youtube.com,” a spokesperson said.

“Comments were temporarily hidden by default within an hour, and we released a complete fix for the issue in about two hours.

Hackers had used JavaScript and HTML code to trigger the malicious pop-ups.

“The thing with a cross-site scripting attack is that it will appear that it is a message being posted by that website, which gives it a certain legitimacy, Graham Cluley of security firm Sophos told BBC News.

“It could be used to show a message that tells you to update your password; it could link to a malicious website; or it could attempt to phish you.”

For now YouTube is back to it’s old self and if you’re visiting the site in the next week I thoroughly recommend you click on the football icon during playing videos to add an authentic Vuvuzela soundtrack.

Related Articles:

MSN Video vs. Google Youtube
Youtube Videos: Playback Problems And Fixes
See Who’s Watching Your Videos on YouTube
Increase your Youtube experience with Greasemonkey
Want Even More Distractions? Try Google+’s Youtube Button

Enjoyed the article?: Then sign-up for our free newsletter or RSS feed to kick off your day with the latest technology news and tips, or share the article with your friends and contacts on Facebook, Twitter or Google+ using the icons below.



About the Author:Mike Halsey is a Microsoft MVP for "Windows Expert". He is also the author of Troubleshooting Windows 7 Inside Out from Microsoft Press and the Windows 7 Power Users Guide, a how-to guide for non-technical Windows users on how to get the best out of Microsoft's new operating system, with step-by-step and quick guides. You can follow Mike on Facebook, Twitter or on his own website The Long Climb

Author: , Monday July 5, 2010 -
Tags:, , , ,


Responses so far:

  1. HNicolai says:

    It wasn’t a cross-site scripting (XSS) flaw, it was a html code injection flaw.
    And when I found out of this, then it took at least 3~4 hours before Google made the “Hide comments”-workaround.

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

Subscribe without commenting

© 2005-2012 Ghacks.net. All Rights Reserved. Privacy Policy - About Us