Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Community > MacNN Lounge > YouTube HTML Inject July 4th Exploit

YouTube HTML Inject July 4th Exploit
Thread Tools
Big Mac
Clinically Insane
Join Date: Oct 2000
Location: Los Angeles
Status: Offline
Reply With Quote
Jul 4, 2010, 08:38 PM
 
Anyone else see the news of the July 4th YouTube exploit that had places like 4chan buzzing this morning? It seems like Google's coders failed to protect the site from a very elementary code inject vulnerability, and once it was learned about by hackers and script kiddies, they were doing things like redirecting popular videos to porn, hijacking browsers in a way that required they be force quit, redirecting to other sites, and the like.

This incident has awakened me to the fact that Google, for all its wealth and for all its PhDs, may not be nearly as good when it comes to even basic web security issues as one would expect. Previously we heard about the Chinese hacking of Google servers - certainly a negative story but one that you could excuse to some degree by assuming those hackers were l337 and that it was a small scale exploit. But this was a large scale, very easy to pull off inject attack (and by easy I mean one short line of code easy) that I would think any first year professional web coder would learn to guard against. I'm looking at Google and its services with a freshly skeptical eye now.
( Last edited by Big Mac; Jul 5, 2010 at 11:22 PM. )

"The natural progress of things is for liberty to yield and government to gain ground." TJ
     
besson3c
Clinically Insane
Join Date: Mar 2001
Location: yes
Status: Offline
Reply With Quote
Jul 4, 2010, 09:56 PM
 
Big Mac: in my experience in working in a big company like this and based on everything I know the problem is usually not the competency of the coders, but the mixing of the tech and business cultures. The politics, business direction/strategy, staffing, and all of that sort of stuff can easily get in the way of the quality of a product, its focus, and its security too, and of course dysfunctional communication can be a hinderance as well.

In a company like Google it might be one department that performs security audits/scans, another that codes the web applications... It could be that the security guys didn't look at this, that they weren't given enough/proper information, that a problem was never patched due to political reasons, etc.

It's obviously pointless to speculate, but my main point is that the coupling of the whole business culture with the geekery creates about 2098230948203948 variables, and often accounts for suckage.
     
Big Mac  (op)
Clinically Insane
Join Date: Oct 2000
Location: Los Angeles
Status: Offline
Reply With Quote
Jul 5, 2010, 11:23 PM
 
besson and I were the only ones interested in this story? That's surprising. . .

"The natural progress of things is for liberty to yield and government to gain ground." TJ
     
besson3c
Clinically Insane
Join Date: Mar 2001
Location: yes
Status: Offline
Reply With Quote
Jul 5, 2010, 11:28 PM
 
Big Mac: that's because we're not losers!
     
Lint Police
Dedicated MacNNer
Join Date: May 2008
Status: Offline
Reply With Quote
Jul 6, 2010, 12:03 AM
 
It's almost like the Government runs them.

cause we're not quite "the fuzz"
     
Rumor
Moderator
Join Date: Feb 2006
Location: on the verge of insanity
Status: Offline
Reply With Quote
Jul 6, 2010, 01:37 AM
 
It could have been bad code from before Google bought youtube.
I like my water with hops, malt, hops, yeast, and hops.
     
Big Mac  (op)
Clinically Insane
Join Date: Oct 2000
Location: Los Angeles
Status: Offline
Reply With Quote
Jul 6, 2010, 02:11 AM
 
Even if that were true, one would hope Google would have code audited everything from YouTube.

"The natural progress of things is for liberty to yield and government to gain ground." TJ
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 06:14 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,