Posts Tagged ‘YouTube’

Cross-site scripting on YouTube

XSS vulnerability in YouTube comments processing allows an attacker to execute arbitrary scripts in the security context. Go on youtube. Choose any video. Add the following script: [php]<script>IF_HTML_FUNCTION?<h1><marquee><font color="red"><u>add your comment here<script>[/php] Update (1): It is better to stay away from YouTube until they fix the vulnerability or at least logging out of YouTube if [...]


Fake YouTube Pages Spreading Malware

Researchers at eSoft Threat Prevention Team have discovered thousands of fake websites that looks like YouTube. The website contains video which leads to installing a downloader Trojan with a less than 20% detection rate according to Virus Total. The site is looking very closely to Youtube with a high quality to make it looks legitimate [...]