Showing posts with label Youtube. Show all posts
Showing posts with label Youtube. Show all posts

Thursday, 11 February 2016

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Thursday, 1 October 2015

Google AdWords For Blue Screen Of Death Scam



Criminals have used Google Adwords to lure users to pages that called a Blue Screen of Death show (BSOD). For resolving the problem should then phone calls. Eventually adjust the telephone scammers that they can fix it for an amount between 199 and 599 dollars, let anti-malware company Malwarebytes know.

To get people to the pages used to lure the BSOD be AdWords, the largest online advertising service from Google. When users via the Google search engine for the term "youtube" searching pull them alongside the search results to see two ads above the results. It seems here that the ads point to YouTube, but loaded into reality the BSOD page. After being informed, Google removed the ads. According to analyst Jerome Segura is consciousness but the best protection against these scams.

Friday, 28 August 2015

Google Chrome Will Pause Flash Ads


From September 1, Google Chrome will automatically pause most Flash ads, so has Google via Google Plus disclosed. In June, Internet giant had already announced that it wanted to pause certain plug-ins, including Adobe Flash Player, in order to reduce power consumption and load times.

Google has long been trying to make Flash redundant. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed via AdWords, which are since February this year automatically converted to HTML5.Google argues that advertisers with Flash ads are working have several options to ensure that their ads are still shown to Chrome users, such as automatically to HTML5 to put out or to do it yourself.

Last month, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop so completely on HTML5 can be switched. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins.

Monday, 24 August 2015

Torrent Tracker Windows Blocks 10 Users


A torrent site where users can download content illegally decided to block Windows 10 users, since the operating system "is nothing more than an espionage tool", so let the administrators know. Visitors to the torrent tracker ITS automatically to a video on YouTube redirected, which claims that all Windows 10 computer monitors.

TorrentFreak reports that also consider two other torrent trackers to not allow users with Windows 10. "Microsoft recently released Windows 10. We want our members to know that we consider to block the operating system on FSC. This means that you no longer running Windows 10 can use the site," according to the administrators of torrent tracker FSC.

Recently, there was a fuss about a Microsoft agreement entered into force on August 1, which states that Microsoft may block pirated games. Some websites think that the agreement applies to Windows 10, but the operating system is not mentioned in the agreement. However, for example, are mentioned Xbox and Windows games from Microsoft, as well as online gaming service Xbox Live.

Thursday, 13 August 2015

Tor Browser Enhances Privacy And YouTube Support


For Internet users who want to protect their anonymity and privacy on the web is a completely new version of Tor Browser appeared. It is the first version of Tor Browser 5.0 . Besides several vulnerabilities that are fixed This version contains several measures to protect user privacy.

For example, there are added protective measures to prevent identification on the basis of key strokes. The NoScript whitelist is reset. NoScript is a Firefox extension that prevents the execution of scripts on websites. NoScript uses a whitelist of domains where scripting is allowed. The reason for the reset is that NoScript previous updates certain areas were added to the whitelist. To avoid repetition NoScript will not be able to update the whitelist. Further supporting the playback of HTML5 video on YouTube improved.

Zero day

Tor Browser is based on Firefox. Recently, a zero-day flaw was used in the PDF reader Firefox to attack users. According to the Tor Project, the developer of Tor Browser, the problem was not present in version 4.5 of Tor Browser. Users of the trial version of Tor Browser 5.0 were vulnerable. However, the attack could not be carried out if the security slider Tor Browser stood tall. The browser has recently acquired a slider that allows users to specify the security level. Updating to the new versions of Tor Browser via the browser or Torproject.org . Globally, 2.5 million people use the Tor network.

Tuesday, 4 August 2015

Organization Reads Alarm About Malware Videos On YouTube


The American organization Digital Citizens Alliance has sounded the alarm about Remote Access Trojans (RATs) and the fact that to find many tutorials on the use of this type of malware on YouTube. Something that both the makers and Google eventually benefit.

Remote Access Trojans existence for many years and give an attacker complete control of the computer of the victim. To install the RAT to a victim is often used social engineering, in which the victim is enticed to open a file and thus infect their computer. It involves, for example the e-mail attachments or files that are exchanged via Skype or social media. Once the victim opens the file, the attacker can for example watch the webcam or to save keystrokes.

Trading

On the internet there are several forums in which computers are traded infected with a RAT, or where images are seen from victims who were filmed secretly through their own webcam. A practice in which in 2008 was warned before. Software for making a RAT is easy to locate over the internet. In addition there are numerous instructional videos on YouTube, according to the Digital Citizens Alliance . Videos which both creators and Google make money because Google shows ads in the videos. "No company, especially one as big as Google, would earn a penny to videos that show the faces of victims and their IP addresses," said the organization. If it is to be YouTube videos now also controlled manually with the Digital Citizens Alliance.

Human Nature

To turn the call force was a lengthy report ( pdf ) published on Remote Access Trojans (the report at the time of writing not available, but still in the cache to find Google). In it is mainly create the impression that consumers nothing against this type of malware can do, rather than focusing on the prevention of an infection caused by a RAT, namely, by no unsolicited attachments, to open files or links.

There will be a security expert to speak which is precisely that people can do anything if they become infected. "Links are meant to be opened. Many people clicking hundreds of links per week," said Megan Horner Blackfin Security. "It goes in. Against human nature it is difficult to do, even if you see something that you should wait." In the conclusion of the report, however, called in short to awareness campaigns. In addition, the Digital Citizens Alliances which investigative agencies have more resources to deal with such crimes and would "hackers" that should be punished violate the privacy of their victims.

Wednesday, 24 June 2015

Kodi Media Center (XBMC) Vulnerable To MITM Attacks



The popular media center Kodi, formerly known as XBMC, contains a vulnerability which attackers between a user and the Internet are able to attack the system. Through Kodi allows users movies, music and other media, for example playback on their TV or sound system.

The software contains a collection of add-ons that allow users popular services like YouTube, Grooveshark and Dropbox can access. Each time Kodi is started watching the software or pre-installed add-ons updates. In the case of a new version is automatically downloaded and installed. The update check takes place entirely over HTTP without encryption, as discovered the Romanian antivirus company BitDefender .

The software asks during the update check to a MD5 hash for the last addons.xml file, which contains information about add-ons. An attacker can send back, in this case a random MD5 hash, which does not have to correspond to the file that is then presented. The attacker could send a specially prepared following addons.xml file indicating that a new version for a particular add-on is available. Then, the attacker must send the correct MD5 hash for his malicious add-on. Once Kodi this add-on installs the malicious Python code running in the add-on to the system.

For their demonstration, the researchers succeeded to download an executable file and place it in the startup directory of the system. It should be noted that an attacker the same privileges as the user running Kodi. Eventually they managed also to steal login details for YouTube and could Dropbox add-on change, so when starting or synchronizing files all content from the local Dropbox directory to a specified FTP server was sent. The Kodi developers are informed by Bitdefender and working on an update. When that appears is unknown.

Saturday, 2 May 2015

Woman Arrested People Via Webcam Spying


In Canada arrested a 27-year-old woman who was spying on people through their own webcam and scared and was also the owner of a large hacking forum with 35,000 members. The woman would Remote Administration Tools (RATs) are used to gain access to computers of people.

Then the woman spying unsuspecting users via their webcam. Also used the woman several ways to harass victims, including by eavesdrop private conversations and victims to address through the speakers. Furthermore, the woman scared her victims by charging pornographic websites.

The startle response of the victims were then recorded and posted on YouTube. Canadian police advises Internet users who want to protect against this kind of attack not to open email from strangers or clicking on suspicious links and the webcam to turn off or cover if it is not used.

Friday, 17 April 2015

YouTube Leak Was Hijacking Reactions Possible


Vulnerability in YouTube made it possible to copy reactions from one video to another video, which was without any user interaction required for here. Reactions on YouTube channels could be hijacked, researchers found Ahmed Aboul-Ela and Ibrahim El-Sayed.

Users comments on YouTube videos and leave channels. YouTube also gives content creators the option to moderate comments before they first appear below the video. If the content creator approves a reaction there is a request to YouTube that contains the video ID and response ID. By changing the reaction ID in the ID of a reaction that was already posted, that reaction was also placed under the video of the moderating content creator.


This happened without the person who had given the response, as well as the creator of the video where he initially responded, here knew anything since. After being informed by the investigators Google had the problem solved within five days and gave the researchers a financial reward for their discovery . Recently had another researcher discovered a vulnerability that made ​​it possible to all YouTube videos to remove .

Friday, 3 April 2015

Sleepless Nights After Infection By Ransomware


An Irish businesswoman was strange to watch when she was a seemingly innocent YouTube link on Facebook and clicked her computer suddenly was infected with ransomware. All files, both business and private, were encrypted. To access they had to pay two bitcoins, which corresponds to 450 euros. She saw eventually forced to purchase the bitcoins and to pay the ransom.

The whole process took two days and gave her sleepless nights, she leaves in front of the Belfast Telegraph know. "It was just a link on Facebook, and it seemed to me it on a YouTube video. I thought it was safe and had no doubts." The woman was especially afraid of losing her private pictures. In addition, the computer also contained all kinds of business data of its business.

Paying the bitcoins was no easy task, so let them know. "The person I bought them wanted to validate me. They had to show a photo ID and ID card. They had to know that I was a real person." After she had paid her files were decrypted after half an hour. It took more than a day before it was operational again. The woman describe the whole event as a very stressful situation. From examination of Threat Track among 250 US IT professionals of medium-sized companies shows that 30% are willing to pay in the event of ransomware.

Thursday, 2 April 2015

Researcher Could Remove Any YouTube Video


A security researcher has discovered a vulnerability in YouTube so he could remove any video on the popular video site. Kamil Hismatullin Google had received a "fair" to search for vulnerabilities in certain Google services. In late January, Google announced a new experimental program for security researcher. Researchers previously already received a financial reward to investigate vulnerabilities.

Hismatullin focused on YouTube Creator Studio, an app that allows users to manage their YouTube channel and statistics to retrieve. Looking for different vulnerabilities ran the researcher at a logic bug, so he could remove any video via a single request. Specifying a video ID with its own session token proved to be enough. Hismatullin reported the problem on a Saturday morning. Yet it quickly by Google was picked up and corrected within a few hours. For his bugmelding received the investigator $ 5,000. As proof, he made demonstration video below.

Wednesday, 18 March 2015

IP Box Can Lock Screen iPhones Brute forcing


Researchers have discovered a device that makes it possible to brute forcing the lock screen of iPhones and iPads. IP Box, as the device is called, would be used by telephone repairmen to bypass the screen lock of iOS. "This obviously has major implications for the safety and of course was something that we wanted to investigate and validate" said researchers MDSec .

They did eventually get to 200 pounds one of the devices. The IP Box appears to simulate via the USB connection to enter the PIN and also tries all possible pin combinations. According to the researchers, this has been known, but the device also works if the option is enabled to delete the data after 10 attempts.

"Our initial analysis indicates that the IP Box to circumvent the restrictions by making direct with the power of the iPhone connection and aggressively to break the flow after each unsuccessful PIN, but before the attempt is synchronized in the Flash memory." Entering a PIN would therefore take about 40 seconds. A four-digit PIN can therefore be outdated in some 111 hours.

The attack has been tested on iOS 8.1. An attack on iOS 8.2 will follow. The research would show that it is possible to have a leak was discovered last year, but this has yet to be confirmed. The researchers made ​​the following video on YouTube in which the device and the attack will be demonstrated.


Monday, 9 February 2015

EFF Also Not Happy With YouTube Without Flash Player


In late January announced that Google's now standard HTML5 for video playback, so users do not have Adobe Flash Player need more, but according to the American civil rights movement EFF this is not a victory or improvement for Internet users.

The Electronic Frontier Foundation (EFF) is also not in favor of Adobe Flash Player, which it describes as a closed technology where regular vulnerabilities are found in exposing millions of users to attack. Switching to HTML5 seems at first sight, therefore an improvement, but it is anything but that, late science fiction writer, journalist and blogger Cory Doctorow know.

The problem is that to play Youtube videos without Flash Player Encrypted Media Extension (EME) is used. According Doctorow a controversial technology that Apple, Microsoft and Google, after consultation with Netflix agreed upon. In the spring of 2013 decided the World Wide Web Consortium (W3C) is behind to rally the extension. Last May, Mozilla joined here. According to the browser developer would be no support for Netflix users lose other browser vendors. To the annoyance of Doctorow, who likens it to "destroy the village to save it."

In the case of YouTube is it now means that users without Adobe Flash Player to view videos. "As long as your browser supports the W3C version of Adobe's proprietary software," says Doctorow. Firefox Users can view all the Youtube videos without Flash, but will in some cases require standardized by W3C Encrypted Media Extension. But who uses proprietary software from Adobe, including Mozilla announced last year. According Doctorow is therefore ultimately nothing changed.

Tuesday, 13 January 2015

CENTCOM's YouTube And Twitter Accounts Hacked By CyberCaliphate



Tonight the YouTube and Twitter accounts from hijacked the US Army. The social media accounts of the US Central Command showed messages from a group calling itself "CyberCaliphate". In addition to the notices published in the YouTube channel propaganda videos of IS terror group.

Screenshot from Twitter (@CENTCOM)

Both the YouTube account as the Twitter account is now inactive. In a statement to US media Central Command confirms that the social media accounts have been hijacked, but does not explain how this could happen. According to the press officer of the White House the impact of a hacked Twitter account can not be compared to a large data theft. Central Command oversees US troops fighting in Iraq, Syria and Afghanistan.

Tuesday, 6 January 2015

Gogo Inflight Internet Issues - "Wifi Service In Aircraft Used Fake Google Certificate"



An American company that offers WiFi in aircraft appears to use a fake Google certificate to filter YouTube, as discovered an employee of Google. It is Gogo Inflight Internet, which include flights on American Airlines, Delta Air Lines and United Airlines offered.

During her flight decided Adrienne Porter Felt, security researcher at the Google Chrome Security Team, YouTube visit and saw a fake certificate was used, in which they have a public tweet sent to Gogo. In response to the controversy surrounding the wifi provider gave yesterday a response. In it, the director that Gogo due to the limited bandwidth some streaming services does not support and various techniques used to block or restrict video streaming.

"Whatever technique we use to limit the bandwidth, the only impact on certain secure video streaming sites and not on the normal safe Internet traffic," says director Anand Chari. "These techniques are used so that anyone who wants the internet during the flight has a consistent browsing experience." Charitable stressed that no user information is collected by the techniques used Critics , however, are outraged and say that the company for blocking or filtering YouTube no need to use fake Google certificate.

Wednesday, 3 December 2014

Google - Captcha Fighter Against Robots

Google has a new captcha developed to distinguish people on websites of robots, whereby it is no longer necessary to solve a puzzle first. CAPTCHAs are used inter alia for the automatic creation of accounts and post spam on websites counter.

To often distinguishable robots people must puzzles and distorted texts are resolved. Google uses recaptcha example, where there are words from books must be retyped. Our own research shows that the search giant artificial intelligence with an accuracy of 99.8% can solve the puzzles. According to Google would therefore be much easier to apply directly to users whether they are human or robot. This allows users to quickly register or use of a service, which also eliminates the annoyance of solving the captcha.



API

A new API (Application Programming Interface) makes this captcha experience now possible. On websites that use the API receives a large number of users the ability to attach a single click that they are not a robot. Although this sounds simple, the underlying technology is complex, according to the search giant. Last year was a special backend developed that performs a risk if users want to solve a captcha.

On the basis of the way in which the user handles were examined with the captcha or the user was a human. The new API is a development of this, which is looked at many factors which indicate that it is a human being. Where does the risk of insufficient evidence to make this decision will appear captcha again. In addition, the API also makes it possible to test other types of captcha's. The new API would now be used on various websites, including Snapchat, WordPress and Humble Bundle.