This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Thursday, April 02, 2015

A Russian Security Researcher can Delete any Youtube Videos Awarded $5000

Kamil Hismatullin, a Russian security bod, found a simple logical vulnerability that allowed him to delete any video from YouTube in one shot.

While looking for Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) flaws in YouTube Creator Studio, Hismatullin came across a simple logical bug that could wipe up any video by just sending an identity number of any video in a post request against any session token.


POST https://www.youtube.com/live_events_edit_status_ajax?action_delete_live_event=1

event_id: ANY_VIDEO_ID
session_token: YOUR_TOKEN


Citing the consequences of the issue, Hismatullin said "this vulnerability could create utter havoc in a matter of minutes in [attackers'] hands who could extort people or [just] disrupt YouTube by deleting massive amounts of videos in a very short period of time."



The researcher reported the bug to Google, and the search engine giant fixed the issue within several hours. Hismatullin won $5,000 cash reward from Google for finding and reporting the critical issue and an extra $1337 under the company’s pre-emptive vulnerability payment scheme.


Hismatullin post on his blog Link

In general I spent 6-7 hours to research, considering that couple of hours I've fought the urge to clean up Bieber's channel haha.

Although it was an early Saturday's morning in SF when I reported issue, Google sec team replied very fast, since this vuln could create utter havoc in a matter of minutes in the bad hands who can used this vulnerability to extort people or simply disrupt YouTube by deleting massive amounts of videos in a very short period of time. It was fixed in several hours, Google rewarded me $5k and luckily no Bieber videos were harmed :D

























Tuesday, March 31, 2015

5 Hosting Companies hacked because they were hosting terrorists web sites

SEA, a pro-hacker group supposed to be aligned with Syrian President Bashar al-Assad, is famous for hacking high-profile websites and targeting leading organisation with its advanced phishing attacks.

The official Twitter account linked to SEA group claimed responsibility for the hack. The group has posted the screenshots of the hacked panels of all the respective web hosting companies.

The group hacked Endurance Group wings, including Bluehost, Justhost, Hostgator, Hostmonster and FastDomain, which are some of the world's leading web hosting companies.

According to SEA group, Endurance Group's BlueHost, JustHost, HostGator and HostMonster were hosting terrorists web sites on their servers, which is why the group hacked them.
It isn’t the first time when the group has hacked some companies, earlier SEA hackers hacked a number of websites for posting content against its Syrian President.

 On its official Twitter account, SEA hackers posted screenshots of the HostMonstor and BlueHost admin panel access which indicates that the group had complete access to the control panel of these hosting companies.




On a separate Tweet, the group has also warned the web hosting companies that next time it will change the DNS settings.

Apart from this, Syrian Electronic Army has also hacked official Twitter account of Bluebox and had tweeted from the hijacked Account. The tweets were then deleted from the account.

The SEA group is the same hackers group famous for its advanced phishing attack and with the help of the same technique they hacked into the Official Twitter account of Xbox Support, Microsoft News, Skype and also defaced the Skype and Microsoft Official Blog pages in the past.