Microsoft’s YouTube Channel Vulnerabilities Exploited as Clips Get Replaced
On Sunday morning someone outside Microsoft seems to have taken possession of the company’s YouTube channel, eliminating all of the videos already loaded (including those relating to the new promotional campaign) and replacing them with video calling for a seemingly meaningless sponsorship.
In place of the official videos and advertising from Microsoft, hackers have included short films, accompanied by messages from the attacker. “I DID NOTHING WRONG I SIMPLY SIGNED INTO MY ACCOUNT THAT I MADE IN 2006,” posted the cracker.
One video called Bingo showed a character from the LA Noire video game. The other video titled ‘post video responses, create new background images for the channel or provide sponsorship’ was displayed on the channel, replacing Microsoft’s official videos. The archived videos were also replaced with short clips “We are sponsoring!” and “Make us a background to get a Subbox!!!”
There’s no details on exactly how someone snuck into Microsoft’s account, but ccording to security firm Sophos, one explanation is that the attacker possibly created a Microsoft account when YouTube was still in nascent stage. The security breach might have occurred on this account, which was probably still attached to the e-mail of the former owner, and Microsoft forgot to update this, leaving the back door wide open.
Microsoft has confirmed the hacking of the YouTube channel and is working with YouTube to restore the service. “We have regained control of the Microsoft channel on YouTube, and we are working to restore all of the original content,” said a Microsoft spokesperson. “We will continue to work with YouTube to ensure safeguards are in place for the future.”
This is not the first time a brand’s YouTube page came under attack. Last week, ‘Sesame Street’ was attacked, with its clips being replaced with porn videos.
Web defacement is on the rise. This week, Fraser Howard and the security researchers of Sophos Labs discovered a new technique to hack corporate web pages by inserting malicious infected PHP codes into the header elements of the front pages of web sites. Earlier this month Microsoft submitted Security Intelligence Report, which stated that 99 percent of attacks exploit known vulnerabilities, saying that malware can break by instinctive force passwords on infected systems. AOL is another recent sufferer, being attacked by a hacker group identifying themselves as HodLuM.
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.