YouTube hit by security concerns
Network Security · 2007
Popular web video site YouTube has been the subject of security exploits that could affect users visiting the site. The exploits, which use YouTube as a decoy to mask a malware download and which also embed malware directly in videos available on the site, are the latest in a series of attacks designed to target the web 2.0 class of applications that generate their value from user input. The first attack, separately identified by security firms Websense and Panda Labs, has been called ‘tubing’. It consists of a trojan delivered by conventional means as an .exe file. When executed, the file opens a web page in the user's default browser that opens a YouTube page containing a video. While the video plays, the Trojan connects to a remote site and downloads data-stealing malware designed to harvest information from the user's computer.