How do they do it? Apparently, they used the wrong HTML, to circumvent the filters Youtube comment on this page. Ebaums HTML injection vulnerabilities found in the comments system popular video site. Some observations were found to start with a tag
Youtube took matters into his hands, and finally turned off all the comments that exploit vulnerabilities HTML. This is a statement released by Google.
"We took swift action to fix cross-site scripting (XSS) vulnerability on youtube.com, which was discovered a few hours ago. Comments have been temporarily hidden by default in an hour, and we released a full fix for the problem in about two hours. We continue to study the vulnerability of to prevent similar problems in the future
0 comments:
Post a Comment