Menu
YouTube flaw allowed copying comments from one video to another

YouTube flaw allowed copying comments from one video to another

Google has fixed the flaw and paid a bug bounty

An Egypt-based security researcher said Google has fixed an interesting vulnerability he and a colleague found in YouTube.

Ahmed Aboul-Ela wrote on his blog that he and a fellow researcher, Ibrahim Mosaad, wanted to find a problem in a feature on YouTube "that not many bug hunters have tested."

They focused on a setting in YouTube that holds comments for review before they're published. If that feature is enabled, comments are then listed in a control panel labeled "held for review."

Aboul-Ela wrote he intercepted the http request that is sent to Google when a comment is approved. The request contains two parameters: "comment_id" and "video_id."

An error is returned if the video_id is changed to a different one, he wrote. But YouTube accepted changing the content_id number to a different video, which then caused the comment to get copied to that video.

"The original comment from the original video doesn't get removed, and the author of the comment does not get notified that his comment is copied onto another video," Aboul-Ela wrote.

The flaw could have been used in many ways. It could be used to make it appear that a video is more popular that it actually is. Or it could have been used to falsely make it appear a celebrity or public figure commented on something, Aboul-Ela wrote.

Google fixed the vulnerability within a week of being notified on March 25 and paid a US$3,133.70 bug bounty.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Read more: Google, Microsoft serve up security treats for productivity suites

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags GooglesecurityExploits / vulnerabilities

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments