YouTube Hack Targets Fans Of Teenager Singer

The fans of singer Justin Bieber have been targetted by hackers who used a cross-site scripting vulnerability on video sharing site YouTube.

Using the vulnerability, the attackers were able to insert HTML code into YouTube pages devoted to Bieber and greet fans with redirects to adult content as well as a numerous pop-up messages, including one claiming the 16-year-old star had been killed in a car accident.

Fans Targeted

The attackers placed the code in the comment section of the pages, prompting Google to temporarily hide comments Sunday by default.

Other pages unrelated to Bieber were reportedly targeted as well.

According to Google, a fix for the issue was rolled out about 2 hours after it was discovered.

“We’re continuing to study the vulnerability to help prevent similar issues in the future,” a Google spokesperson told eWEEK on Sunday.

Code Loopholes

The vulnerability allowed the attackers to bypass the filter normally used to police YouTube comments.

“Clearly YouTube is a big target, as it has so many millions of visitors every day, and you would hope that their web team will investigate what went wrong with their processes, and explore if they are reviewing code properly before it is made live to ensure that loopholes aren’t left in their code in future,” noted Graham Cluley, senior technology consultant at Sophos.

Poor Justin Bieber has also unwittingly committed himself to a tour of North Korea, after he asked fans to vote on Twitter which country he should visit next. Pranksters “clickswarmed” more than half a million votes for North Korea … although it is unlikely Bieber would get permission to responded from Kim Jong Il to tour there.

By a strange coincidence, Internet hackers seem to have a preference for teen popsters that happen to be Canadian. Girl music sensation Avril Lavigne had her name immortalised by the Lirva worm in 2003

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Creating Deepfake Porn Without Consent To Become A Crime

People who create sexually explicit ‘deepfakes’ of adults will face prosecution under a new law…

12 hours ago

Google Fires 28 Staff Over Israel Protest, Undertakes More Layoffs

Protest at cloud contract with Israel results in staff firings, in addition to layoffs of…

13 hours ago

Russia Already Meddling In US Election, Microsoft Warns

Microsoft warns of Russian influence campaigns have begun targetting upcoming US election, albeit at a…

15 hours ago

EU To Drop Microsoft’s OpenAI Investment Probe – Report

Microsoft to avoid an EU investigation into its $13 billion investment in OpenAI, after EC…

18 hours ago

US Provides Assurances For Julian Assange Extradition

As President Biden 'considers' request to drop Julian Assange extradition, US provides assurances to prevent…

20 hours ago