Post Reply 
Youtube HTML exploit
Author Message
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1294
Offline
Post: #1
Youtube HTML exploit
I don't visit Youtube often, but some of you who do may have seen this?  Apparently, a HTML exploit was discovered in Youtube's commenting system.  By starting the comment with "<script>", one could insert arbitrary HTML onto the page (or something like that).  The actual tag gets filtered properly, but everything after doesn't.

http://www.google.com/support/forum/p/yo...9910&hl=en

I think comments are hidden now - unsure if the issue is actually fixed or not.

I guess 4chin SUCK people had a bit of a field day with this.

Random comment:
Quote:The evolution of this bug exploit was quite interesting to follow up close.

At first it simply prevented any further comments to be posted.
Then text was added.
Then the text was scrolling.
Suddenly, the entire page was blacked out except for the added text.

And that's when the more technical minded people realized much much more was possible.
Bam! Popups!
Infinite popups that lead to browser crashes!
Page redirects to shock sites!
The most sophisticated version I saw actually replaced the Youtube video in-place with the 1man1jar video..

And when the exploit was blocked in the comments, it had a small resurgence as video reply title, before being smacked down once more.

Glorious.
05/07/2010 05:37 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Youtube HTML exploit - ZiNgA BuRgA - 05/07/2010 05:37 AM
RE: Youtube HTML exploit - S7* - 05/07/2010, 05:58 AM
RE: Youtube HTML exploit - diego - 05/07/2010, 06:46 AM
RE: Youtube HTML exploit - eKusoshisut0 - 05/07/2010, 07:29 AM
RE: Youtube HTML exploit - S7* - 05/07/2010, 07:13 AM
RE: Youtube HTML exploit - S7* - 05/07/2010, 07:47 AM
RE: Youtube HTML exploit - Gadget - 05/07/2010, 07:56 AM
RE: Youtube HTML exploit - u_c_taker - 05/07/2010, 10:18 AM
RE: Youtube HTML exploit - trademark91 - 05/07/2010, 10:25 AM
RE: Youtube HTML exploit - Mythos - 05/07/2010, 02:24 PM
RE: Youtube HTML exploit - Shady - 05/07/2010, 04:42 PM
RE: Youtube HTML exploit - diego - 05/07/2010, 04:47 PM
RE: Youtube HTML exploit - Shady - 05/07/2010, 04:49 PM
RE: Youtube HTML exploit - Silvertie - 05/07/2010, 06:41 PM
RE: Youtube HTML exploit - Ninja88 - 05/07/2010, 11:10 PM
RE: Youtube HTML exploit - S7* - 06/07/2010, 02:17 AM
RE: Youtube HTML exploit - ZiNgA BuRgA - 06/07/2010, 03:34 AM
RE: Youtube HTML exploit - Joom - 07/07/2010, 11:39 AM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

 Quick Theme: