Popular video sharing website Youtube is riddled with security vulnerabilities according to an independent security researcher.
In an open letter to YouTube owner's Google, Christian Matthies said he would publicly disclose over 40 bugs he said he found on the site.
Most of the flaw concern cross-site scripting flaws which allow hackers to inject malicious code into legitimate website in order to steal personal information on website visitors. Most of the exploits allow hackers to infect user profiles with malware that could spread through the internet and steal users log-in details.
"Just like other major social networking sites (or even more), YouTube is responsible for the privacy and security of hundreds of millions of users," said Matthies.
"Having security holes is one thing but not responding to vulnerability reports is totally unacceptable and certainly not conform to your commitment to data security," he said. "Taking that into account I'm going to have one last try and give you two weeks from now to contact me. If you don't, I am obliged to disclose all vulnerabilities in public."
via theregister






















no comments





4 comments























