Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-19-2006, 05:36 PM   #1
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
so if a mod makes himself look retarded...

they just close the thread?

lol, interesting.

http://www.gfy.com/fucking-around-and-business-discussion/678875-gfy-embed-youtubes.html
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:43 PM   #2
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode

i don't see how it is possible though
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:46 PM   #3
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by Jace View Post
yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode

i don't see how it is possible though
My 100k users surfer board is now vulnerable, I would love to know that too
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:50 PM   #4
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by Tuga View Post
My 100k users surfer board is now vulnerable, I would love to know that too
yup, me too, I don't have a crazy board with tons of members, but I have a buddy that is going to install that on his board, and if there is a vunerability, I would like to know about it

Last edited by Jace; 11-19-2006 at 05:51 PM..
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:51 PM   #5
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
Quote:
Originally Posted by Jace View Post
yeah, i wish TD would expand on what exploits could be done with that youtube addition to the bbcode
I doubt we will ever see that
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:53 PM   #6
minusonebit
So Fucking Banned
 
Join Date: Feb 2006
Posts: 7,391
I bet TD has his finger on the ban button... trying to restrain himself...
minusonebit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:54 PM   #7
TexasDreams
former Miserable Admin :)
 
Join Date: Oct 2003
Location: Somewhere in Cali
Posts: 4,700
Quote:
Originally Posted by nofx View Post
When I see a request that is retarded, yes.
__________________
ICQ: 168-914-369 >>> sysop [at] TexasDreams [dot] com
TexasDreams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:54 PM   #8
biftek
So Fucking Banned
 
Join Date: Jan 2005
Location: Victoria, Australia
Posts: 1,030
well i haven't seen any exploits for that bbcode , but i have read about some bogus youtube clips that infect the viewer with zango
http://www.spywareremovalnews.com/ne...icle-1102.html
biftek is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:54 PM   #9
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by minusonebit View Post
I bet TD has his finger on the ban button... trying to restrain himself...
with what reason?
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:54 PM   #10
crocop
Confirmed User
 
Join Date: Oct 2006
Posts: 205
i dont see the problem with that code
__________________

crocop is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:54 PM   #11
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:56 PM   #12
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by fusionx View Post
The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals
No video in my board autoplays, what option is that?
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:57 PM   #13
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by TexasDreams View Post
When I see a request that is retarded, yes.
Oh really? Half the threads in GFY ARE RETARDED and I dont see you closing them.

The only retarded thing in that thread is.... well you know what.
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 05:59 PM   #14
TexasDreams
former Miserable Admin :)
 
Join Date: Oct 2003
Location: Somewhere in Cali
Posts: 4,700
Quote:
Originally Posted by biftek View Post
well i haven't seen any exploits for that bbcode , but i have read about some bogus youtube clips that infect the viewer with zango
http://www.spywareremovalnews.com/ne...icle-1102.html
That's actually easier than most might think.
__________________
ICQ: 168-914-369 >>> sysop [at] TexasDreams [dot] com
TexasDreams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:01 PM   #15
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
TexasDreams doesn't know shit about running web forums.

I don't know why adult.com won't hire a real admin.
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:02 PM   #16
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by TexasDreams View Post
That's actually easier than most might think.
He is talking about FAKE you tube clips and that bbcode wouldnt work with that shit, you really dont have a clue do you? That's not a problem, noone knows everything, but you should really try to learn a little bit instead of acting like a fool. This is a webmaster board you know? Some people here know a few things about the interweb. Learn from them.
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:13 PM   #17
2HousePlague
CURATOR
 
Join Date: Jul 2004
Location: the attic
Posts: 14,572
Quote:
Originally Posted by TexasDreams View Post
When I see a request that is retarded, yes.
You can't blame me for being oblivious to security threats - I'm not a security guy. The other stuff is subjective.

2hp
__________________
tada!
2HousePlague is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:14 PM   #18
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by fusionx View Post
The only downside to embedding youtube and other vids is when people quote and keep the vid in the quote, and autoplay is turned on, it really fucks up your browsing experience ...

or, if multiple people post in the same thread, etc. Imagine 20 vids playing, starting at 1 second intervals
most youtube videos don't autoplay when they are embedded off the youtube site

same with pornotube...hehe..but you knew that
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:15 PM   #19
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by 2HousePlague View Post


You can't blame me for being oblivious to security threats - I'm not a security guy. The other stuff is subjective.

2hp
I wish he would explain it more detail, I am genuinely curious as to what would happen in regards to security, I have seen tons of forums that did it, and not one has been hacked or ran into issues
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:18 PM   #20
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
from vbulletins site:

Quote:
Are there any security issues with this??
Quote:
The embeded flash is running off youtube's server and there's no html to embed the code. It's all bb code and you're only posting the end numerical value of the video's url.
even the vbulletin experts say there is no security risk
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:20 PM   #21
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by Jace View Post
even the vbulletin experts say there is no security risk
Someone should block those guys, they're retarded
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:23 PM   #22
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by Tuga View Post
Someone should block those guys, they're retarded
hahahahaha
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:24 PM   #23
PMdave
Confirmed User
 
Join Date: Dec 2003
Posts: 1,517
uhmmm.... isn't that "youtube installs zango"-story based on the fake Yootube.info movies?
PMdave is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:24 PM   #24
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
Quote:
Originally Posted by Tuga View Post
Someone should block those guys, they're retarded
bhahahahhaha
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:24 PM   #25
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by PMdave View Post
uhmmm.... isn't that "youtube installs zango"-story based on the fake Yootube.info movies?
And how the hell is that related to what we are talking about?
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:25 PM   #26
EdgeXXX
Confirmed User
 
EdgeXXX's Avatar
 
Join Date: Nov 2005
Location: Secretely plotting a hostile takeover
Posts: 5,816
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
__________________
.
.
.
.

I have a sig
EdgeXXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:27 PM   #27
2HousePlague
CURATOR
 
Join Date: Jul 2004
Location: the attic
Posts: 14,572
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
Is that possible? How could malicious code survive the flash encryption by Youtube?

2hp
__________________
tada!
2HousePlague is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:28 PM   #28
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
Ok now you got me interested, but I would like you to get into more detail about it. They can put a script on a video and host it on youtube? And what kind of stuff can that script do to a site that is just displaying the youtube player? I really would like to know.
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:28 PM   #29
stickyfingerz
Doin fine
 
stickyfingerz's Avatar
 
Industry Role:
Join Date: Oct 2005
Posts: 24,983
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
I dont think youtube allows videos with action script embedded does it? I know Ive tried it with a simliar site of a pornographic nature and the video was automatically rejected.
stickyfingerz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:40 PM   #30
CaptainHowdy
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,567
Someone close this thread please...
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 06:40 PM   #31
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
well, isn't IE7 going to be a mandatory download here soon? nothing active or action gets by IE7 for me so far....any time anything tries to run it stops it and prompts me

happened with Zango too, Zango tried to install on my computer and IE7 said NOPE!
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 07:17 PM   #32
KrisKross
Confirmed User
 
KrisKross's Avatar
 
Join Date: Jan 2006
Location: Canada
Posts: 5,024
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
If what you're suggesting is possible, then YouTube would have been raped to hell and back a long time ago.

Of course script kiddies have taken notice. Hell, I'm not even a script kiddie and it was one of the first thoughts that crossed my mind when I first came across YouTube.
__________________
KrisKross is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:01 PM   #33
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:03 PM   #34
minusonebit
So Fucking Banned
 
Join Date: Feb 2006
Posts: 7,391
heh, see sig.
minusonebit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:05 PM   #35
2HousePlague
CURATOR
 
Join Date: Jul 2004
Location: the attic
Posts: 14,572
Quote:
Originally Posted by madawgz View Post
maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
Actually, you don't even have to past the whole URL, just the identifier code from the end -- like this


2hp
__________________
tada!
2HousePlague is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:19 PM   #36
Kimo
...
 
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
leave that boi alone
__________________
...
Kimo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:24 PM   #37
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
Quote:
Originally Posted by madawgz View Post
maybe have the adult team write a custom script so all we have to do is paste the youtube url, and the script will extract the code and put it on the page automatically
yeah.. that's what the bb code mod would do

PHP Code:
[youtube]http://www.youtube.com/watch?v=aAP_pxMqmr4[/youtube] 
we built a media tag that plays vids, audio and flash movies from specific sites.. pretty easy for the users, and secure for us.
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:27 PM   #38
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by fusionx View Post
yeah.. that's what the bb code mod would do

PHP Code:
[youtube]http://www.youtube.com/watch?v=aAP_pxMqmr4[/youtube] 
we built a media tag that plays vids, audio and flash movies from specific sites.. pretty easy for the users, and secure for us.
actually, the youtube one is even cooler

it just does this



no url even necessary

you can do the same with pornotube, no installs or code rewrites necessary
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:27 PM   #39
MaddCaz
Confirmed User
 
Join Date: Mar 2006
Location: Illinois
Posts: 9,483
Texas said FUCKIT!!!
MaddCaz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 08:59 PM   #40
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
Quote:
Originally Posted by Tuga View Post
No video in my board autoplays, what option is that?
It's dependent on the player
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 09:16 PM   #41
Bro Media - BANNED FOR LIFE
MOBILE PORN: IMOBILEPORN
 
Join Date: Jan 2004
Location: Tinseltown NL
Posts: 16,502
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
you don't know much about how YouTube works do you?

you upload a mpg, avi, or mov file, not a flash file, you cannot put actionscript for flash, in an mpg/avi/mov their servers convert it to a FLV file, not even flash, flv can't have actionscript either, so no, theres is no possible way for someone to cause harm or anything to ones computer by uploading a movie to youtube...

...plus you think Youtube/Google is stupid enough to let shit like that slide? they got programs that catch that shit, i doubt a big company like google, or hell even the guys who started youtube, being ex paypal programmers would even just "overlook" a security flaw like that...
Bro Media - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 09:19 PM   #42
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
Quote:
Originally Posted by Jace View Post
actually, the youtube one is even cooler

it just does this



no url even necessary

you can do the same with pornotube, no installs or code rewrites necessary

It's easy to modify it that way.. we allow several media sources with the same tag, so we just tell the user to paste the url supplied by the host.
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 09:57 PM   #43
studiocritic
Confirmed User
 
Join Date: Jun 2005
Location: Irvine, CA
Posts: 2,442


thread.. closing..
__________________
254342256
studiocritic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 10:16 PM   #44
Masterchief
Confirmed User
 
Join Date: Jun 2006
Posts: 530
Quote:
Originally Posted by EdgeXXX View Post
Actually, the vulnerability that it opens has nothing to do with HTML or BBCode. It has to do with the possibility of malicious ActionScript embedded in the "videos". Luckily, it's not too much of a danger ATM, as most scriptkiddies haven't really taken notice of it yet. Then again, nothing is ever a problem until all hell breaks loose.
FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.
Masterchief is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 11:28 PM   #45
studiocritic
Confirmed User
 
Join Date: Jun 2005
Location: Irvine, CA
Posts: 2,442
Quote:
Originally Posted by Masterchief View Post
FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.
this is correct.. same reason myspace allows it now. those tags render flash harmless.
__________________
254342256
studiocritic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-19-2006, 11:35 PM   #46
AsianDivaGirlsWebDude
Purveyor, Fine Asian Porn
 
AsianDivaGirlsWebDude's Avatar
 
Industry Role:
Join Date: Jul 2004
Location: San Francisco Bay Area
Posts: 38,323
Quote:
Originally Posted by Madrox View Post
you don't know much about how YouTube works do you?

you upload a mpg, avi, or mov file, not a flash file, you cannot put actionscript for flash, in an mpg/avi/mov their servers convert it to a FLV file, not even flash, flv can't have actionscript either, so no, theres is no possible way for someone to cause harm or anything to ones computer by uploading a movie to youtube...

...plus you think Youtube/Google is stupid enough to let shit like that slide? they got programs that catch that shit, i doubt a big company like google, or hell even the guys who started youtube, being ex paypal programmers would even just "overlook" a security flaw like that...
TD is smarter than Paypal/YouTube/Google. That's why he works for Adult.com...

ADG Webmaster
AsianDivaGirlsWebDude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 12:05 AM   #47
EdgeXXX
Confirmed User
 
EdgeXXX's Avatar
 
Join Date: Nov 2005
Location: Secretely plotting a hostile takeover
Posts: 5,816
Quote:
Originally Posted by 2HousePlague View Post


Is that possible? How could malicious code survive the flash encryption by Youtube?

2hp
Well, the problem is not the code surviving the FLV encryption, the danger is of the malicious code hijacking the encoding subroutine before it even begins.


Quote:
Quote:
Originally Posted by Tuga View Post
Ok now you got me interested, but I would like you to get into more detail about it. They can put a script on a video and host it on youtube? And what kind of stuff can that script do to a site that is just displaying the youtube player? I really would like to know.

Quote:
Originally Posted by stickyfingerz View Post
I dont think youtube allows videos with action script embedded does it? I know Ive tried it with a simliar site of a pornographic nature and the video was automatically rejected.
The problem is not so much a matter of what exploits are known at this very moment, rather what exploitable weaknesses exist that no one has discovered yet. The transition from all content (swf vids) being stored and accessed through a FMS to this new generation of dynamic-loading external FLVs has come about a much greater rate than was initially anticipated (and the increased demand is pushing up development deadlines and cutting test time prior to release).


Quote:
Originally Posted by Jace View Post
well, isn't IE7 going to be a mandatory download here soon? nothing active or action gets by IE7 for me so far....any time anything tries to run it stops it and prompts me

happened with Zango too, Zango tried to install on my computer and IE7 said NOPE!
True, but unfortunately that is only for now. Once the blackhats have time enough to play with IE7 and find it's potential weaknesses, it will be open season on IE again.

Quote:
Originally Posted by KrisKross View Post
If what you're suggesting is possible, then YouTube would have been raped to hell and back a long time ago.

Of course script kiddies have taken notice. Hell, I'm not even a script kiddie and it was one of the first thoughts that crossed my mind when I first came across YouTube.
That's just it (it's kind of complicated... or at least, difficult to explain), we do know that it is possible, we just don't know how. Fortunately neither do they. Basically, it's a race to see who can figure it out first. At the moment (and for the foreseeable future), everything is fine and secure. What the future holds, however, is anybody's guess.
__________________
.
.
.
.

I have a sig
EdgeXXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 12:20 AM   #48
EdgeXXX
Confirmed User
 
EdgeXXX's Avatar
 
Join Date: Nov 2005
Location: Secretely plotting a hostile takeover
Posts: 5,816
Quote:
Originally Posted by Masterchief View Post
FYI, there's 2 options that render those attacks completely useless, try looking up on the "allowScriptAccess" and "allowNetworking" tags.
This is true. But what happens if someone discovers a way to circumvent or override those method tags? Keep in mind, those very methods were just recently adapted due to a weakness discovered in previous platforms.
__________________
.
.
.
.

I have a sig
EdgeXXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 12:21 AM   #49
AsianDivaGirlsWebDude
Purveyor, Fine Asian Porn
 
AsianDivaGirlsWebDude's Avatar
 
Industry Role:
Join Date: Jul 2004
Location: San Francisco Bay Area
Posts: 38,323
Good advice - be afraid of the unknown...

ADG Webmaster
AsianDivaGirlsWebDude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 12:21 AM   #50
georgeyw
58008 53773
 
georgeyw's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: Australia
Posts: 9,864
Quote:
Originally Posted by TexasDreams View Post
When I see a request that is retarded, yes.
How is it a vulnerability? It only plays youtube videos.

I've added it to one of my boards cos it's far better than seeing all those shitty youtube links everywhere
__________________
TripleXPrint on Megan Fox
"I would STILL suck her pussy until her face caved in. And then blow her up and do it again!"
georgeyw is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.