<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="80" t0="1283905803638">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>221486</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] Web Application Security Insights">202615</OwnerID>
        <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
        <CreateTime Title="2008-12-22 16:17:00 EST">1229980620566</CreateTime>
        <ModifyTime Title="2008-12-22 20:50:33 EST">1229997033645</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>YouTube:  Real World Hacking Example</Name>
        <Summary>CSRF vulnerabilities discovered in almost every action a user could perform on YouTube</Summary>
        <Description>&lt;p&gt;&lt;a href="http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks"&gt;&lt;img alt="YouTube - Real World Hacking Example" hspace="10" src="http://www.cenzic.com/images/blog/youtube.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;YouTube is the second big-brand company that we are featuring from Bill Zeller&amp;rsquo;s recent &lt;a title="CSRF paper on these popular vulnerabilities" href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;paper&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and &lt;a title="CSRF vulnerabilities found on 4 big Websites" href="http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;post&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; that got hacked through a CSRF vulnerability.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;Zeller discovered CSRF vulnerabilities in nearly every action a user could perform on YouTube.&amp;nbsp; Specific details are described in the paper.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Here are a few examples of what an attacker could do on YouTube via the CSRF vulnerabilities:&amp;nbsp; &lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Add videos to a user's &amp;quot;Favorites,&amp;quot; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Add himself to a user's &amp;quot;Friend&amp;quot; or &amp;quot;Family&amp;quot; list,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Send arbitrary messages on the user's behalf,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Flag videos as inappropriate,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Automatically share a video with a user's contacts, &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;font color="#333333"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;Subscribe a user to a &amp;quot;channel&amp;quot; (a set of videos published by one person or group) and, &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: normal; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;/span&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font color="#333333"&gt;&lt;font size="3"&gt;&lt;span lang="EN" style="COLOR: red; FONT-FAMILY: Wingdings; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-ansi-language: EN; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: Ignore"&gt;&lt;font size="3"&gt;&amp;sect;&lt;/font&gt;&lt;span style="FONT-WEIGHT: normal; FONT-SIZE: 7pt; LINE-HEIGHT: normal; FONT-STYLE: normal; FONT-VARIANT: normal"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-ansi-language: EN"&gt;&lt;font color="#000000"&gt;&lt;font color="#333333"&gt;Add videos to a user's &amp;quot;QuickList&amp;quot; (a list of videos a user intends to watch at a later point).&lt;/font&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;According to the report, YouTube has fixed these vulnerabilities. &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>hack</Keyword>

                 <Keyword>YouTube</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Popular Websites Vulnerable to Cross-Site Request Forgery Attacks</Title>

                  <Synopsis>4 real-world example of how hackers attack Websites</Synopsis>

                  <URL>http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks</URL>

        </Link>

                 <Link>
                  <Title>Cross-Site Request Forgeries: Exploitation and Prevention</Title>

                  <Synopsis>Read this 13 page paper on CSRF</Synopsis>

                  <URL>http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>eswanson</RemoteUser>

                <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] Web Application Security Insights">202615</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/Cenzic/web</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>edit-item</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>left</Name>

                <Model>blogsite/Cenzic/left-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>right</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>wide</Name>

                <Model>blogsite/Cenzic/wide-content</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">202621</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/Cenzic/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>edit-item</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>left</Name>

                 <Model>blogsite/Cenzic/left-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>right</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>wide</Name>

                 <Model>blogsite/Cenzic/wide-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
