PDA

View Full Version : Anyone else noticed the XSS attack on youtube?



BenAshton24
July 4th, 2010, 02:26 PM
Probably best to avoid videos today... I noticed a few redirects among all the spam and marquees :P

Sslaxx
July 4th, 2010, 02:43 PM
Assclowns. What's new?

CharlesA
July 4th, 2010, 02:49 PM
It's youtube.. Lol.

dragos240
July 4th, 2010, 03:04 PM
Isn't happening here. links?

dragos240
July 4th, 2010, 03:07 PM
Nevermind I got a goatse redirect:-&

LarsKongo
July 4th, 2010, 03:09 PM
Read that it's some sort of html injection in the comments that anons are having fun with. A rather simple security hole that Google should've tested long ago.

Phrea
July 4th, 2010, 03:15 PM
Confirmed, anon is indeed having fun.

Phrea
July 4th, 2010, 03:23 PM
<script>IF_HTML_FUNCTION?<h1><marquee><font color="red"><b>Text here.<script>

That's one of them.

BenAshton24
July 4th, 2010, 03:25 PM
I want to know what's going to happen on 07/12/2010 (Scrnsht 2)

Also how did google let this happen when it's such an easy vulnerability to secure...

FuturePilot
July 4th, 2010, 03:41 PM
/me hugs NoScript

Helkaluin
July 4th, 2010, 04:19 PM
/me hugs NoScript
Seeing that the 'exploit' actually injects Javascript that will be fed from the youtube.com domain itself, I don't see that NoScript will protect your from them at all unless you block scripts from youtube.com... which actually will result in no videos.

Oh well. Google fixed it now anyway.

LarsKongo
July 4th, 2010, 04:31 PM
Seeing that the 'exploit' actually injects Javascript that will be fed from the youtube.com domain itself, I don't see that NoScript will protect your from them at all unless you block scripts from youtube.com... which actually will result in no videos.
It does help a little. Any 3rd party sites you may be redirected to won't be able to run any malicious scripts.

mr-woof
July 4th, 2010, 06:00 PM
i love no script

undecim
July 4th, 2010, 07:08 PM
Well, with noscript, you need to have youtube blocked, but you can still click on the flash video to allow just that video.

urukrama
July 4th, 2010, 07:21 PM
I don't have the problem in Elinks. :)