Audio By Carbonatix
YouTube has been forced to fix a flaw allowing hackers to bombard users with fake pop-up messages and redirect them to adult sites.
Hackers placed code in the comments section, under targeted videos, that would run when people watched the clip.
In some cases, a pop-up screen appeared reporting that the Canadian singer, Justin Beiber, had died in a car crash.
Google, which owns the YouTube, said that it had fixed the problem "about two hours" after it was discovered.
"We took swift action to fix a cross-site scripting (XSS) vulnerability on youtube.com," a spokesperson said.
"Comments were temporarily hidden by default within an hour, and we released a complete fix for the issue in about two hours.
Nasty attacks
Cross-site scripting (XSS) vulnerabilities are relatively simple attacks that allow hackers to place code into web pages.
In the YouTube incident, hackers used JavaScript code and HTML, both commonly used on web pages.
Security experts said that although in most cases the code was relatively benign, it has been used for more malicious purposes.
"The thing with a cross-site scripting attack is that it will appear that it is a message being posted by that website, which gives it a certain legitimacy, Graham Cluley of security firm Sophos told BBC News.
"It could be used to show a message that tells you to update your password; it could link to a malicious website; or it could attempt to phish you."
Phishing is a common tactic used by cybercriminals and involves using fake websites to lure people into revealing details such as bank accounts or login names.
"I've seen nasty XSS attacks that are used to fake whole login screens and we know how many people use same passwords for multiple accounts," said Bojan Zdrnja of the Internet Storm Centre in a blog post.
Mr Cluley said that repsonsibility for these kinds of vulnerabilites was down down to how securely a website was written.
"Web programmers need to be much more careful with their code."
Google said it was "continuing to study the vulnerability to help prevent similar issues in the future".
When the vulnerability was first reported, rumours suggested that YouTube was infected with a virus.
Source: BBC
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
2026 FIFA World Cup: What African fans will pay to watch their teams
2 hours -
2026 World Cup: How FIFA priced Africa’s ordinary fan out of the tournament – and why the gap with the rest of the world is impossible to ignore
2 hours -
Creative industries ‘incredibly worried’ about OpenAI-Disney deal
2 hours -
Low condom use among young people in Volta Region disheartening – AIDS Commission
3 hours -
Prada to launch $930 ‘Made in India’ Kolhapuri sandals after backlash
3 hours -
Gov’t moves to fix Armed Forces housing crisis with 2000 new units and jets
3 hours -
Boy, 13, shot dead as youth torch mining vehicles in Adelekezu
3 hours -
‘Architects of AI’ named Time Magazine’s Person of the Year
4 hours -
GPL 2025/26: Berekum Chelsea edge Hohoe United to end winless run
4 hours -
GPL 2025/26: Mensah’s penalty helps Bechem United beat Eleven Wonders
4 hours -
Did Ghana need 110 brand new hospitals at once?
5 hours -
Benin: Ex-president’s son arrested after foiled coup attempt
5 hours -
Reconsidering Ghana’s presidential age limit: Why Article 62(b) of the 1992 Constitution deserves review
5 hours -
ECOWAS unanimously endorses President Mahama for African Union chairmanship
5 hours -
Douri-Naa predicts victory for ‘Second Dombo’ Bawumia in NPP primaries and 2028 election
5 hours
