Showing posts with label Youtube Videos. Show all posts
Showing posts with label Youtube Videos. Show all posts

Friday, 17 April 2015

YouTube Leak Was Hijacking Reactions Possible


Vulnerability in YouTube made it possible to copy reactions from one video to another video, which was without any user interaction required for here. Reactions on YouTube channels could be hijacked, researchers found Ahmed Aboul-Ela and Ibrahim El-Sayed.

Users comments on YouTube videos and leave channels. YouTube also gives content creators the option to moderate comments before they first appear below the video. If the content creator approves a reaction there is a request to YouTube that contains the video ID and response ID. By changing the reaction ID in the ID of a reaction that was already posted, that reaction was also placed under the video of the moderating content creator.


This happened without the person who had given the response, as well as the creator of the video where he initially responded, here knew anything since. After being informed by the investigators Google had the problem solved within five days and gave the researchers a financial reward for their discovery . Recently had another researcher discovered a vulnerability that made ​​it possible to all YouTube videos to remove .

Thursday, 2 April 2015

Researcher Could Remove Any YouTube Video


A security researcher has discovered a vulnerability in YouTube so he could remove any video on the popular video site. Kamil Hismatullin Google had received a "fair" to search for vulnerabilities in certain Google services. In late January, Google announced a new experimental program for security researcher. Researchers previously already received a financial reward to investigate vulnerabilities.

Hismatullin focused on YouTube Creator Studio, an app that allows users to manage their YouTube channel and statistics to retrieve. Looking for different vulnerabilities ran the researcher at a logic bug, so he could remove any video via a single request. Specifying a video ID with its own session token proved to be enough. Hismatullin reported the problem on a Saturday morning. Yet it quickly by Google was picked up and corrected within a few hours. For his bugmelding received the investigator $ 5,000. As proof, he made demonstration video below.

Monday, 9 February 2015

EFF Also Not Happy With YouTube Without Flash Player


In late January announced that Google's now standard HTML5 for video playback, so users do not have Adobe Flash Player need more, but according to the American civil rights movement EFF this is not a victory or improvement for Internet users.

The Electronic Frontier Foundation (EFF) is also not in favor of Adobe Flash Player, which it describes as a closed technology where regular vulnerabilities are found in exposing millions of users to attack. Switching to HTML5 seems at first sight, therefore an improvement, but it is anything but that, late science fiction writer, journalist and blogger Cory Doctorow know.

The problem is that to play Youtube videos without Flash Player Encrypted Media Extension (EME) is used. According Doctorow a controversial technology that Apple, Microsoft and Google, after consultation with Netflix agreed upon. In the spring of 2013 decided the World Wide Web Consortium (W3C) is behind to rally the extension. Last May, Mozilla joined here. According to the browser developer would be no support for Netflix users lose other browser vendors. To the annoyance of Doctorow, who likens it to "destroy the village to save it."

In the case of YouTube is it now means that users without Adobe Flash Player to view videos. "As long as your browser supports the W3C version of Adobe's proprietary software," says Doctorow. Firefox Users can view all the Youtube videos without Flash, but will in some cases require standardized by W3C Encrypted Media Extension. But who uses proprietary software from Adobe, including Mozilla announced last year. According Doctorow is therefore ultimately nothing changed.

Friday, 23 January 2015

Tubrosa Trojan: "Botnet Infected Computers Makes YouTube Videos"


Cybercriminals use infected computers to watch videos on YouTube, where they ultimately paid for by Google hope to be. Furthermore it is on computers even Adobe Flash Player installed to allow this form of advertising fraud. YouTube pays video creators through a special affiliate program, whereby ads are displayed in the videos. The more people view the videos, the greater the reward. A Swedish gamer with the alias "Pewdiepie" It is estimated that each year 13 million earn his YouTube videos.

For years, botnets are used for advertising fraud, where cybercriminals have infected computers clicking on ads or only view out. According to anti-virus company Symantec have these cybercriminals now shifted their field to YouTube. A few weeks ago, researchers discovered the company's new click fraud malware that infected computers used to artificially inflate the number of times a YouTube video was viewed. Through the affiliate program, the cybercriminals can then redeem their activities.


The attack starts with an e-mail attachment or link that points to the malware. Once activated the malware download a file with thousands of YouTube videos that need to view the computer. Then the malware opens videos in the background to keep the activities hidden from the user. The malware will even update or install Adobe Flash Player to view the videos. The Tubrosa Trojan responsible for these activities would mainly in South Korea, India and Mexico are active. Google late in a statement that it knows of the malware and advertisers protects against the ad fraud.