Tuesday, April 20, 2021
Androidlic
No Result
View All Result
  • Home
  • Android Mobile
  • Android apk
  • Android Tablets
  • Android police
  • Android TV
  • Android watches
  • More
    • HTC Mobiles
    • Huawei
    • Infinix
    • LG Mobiles
    • Nokia
    • Smartphones
    • Sony Tablets
    • Tablets
    • Techno
  • Androidlic Forum
No Result
View All Result
  • Home
  • Android Mobile
  • Android apk
  • Android Tablets
  • Android police
  • Android TV
  • Android watches
  • More
    • HTC Mobiles
    • Huawei
    • Infinix
    • LG Mobiles
    • Nokia
    • Smartphones
    • Sony Tablets
    • Tablets
    • Techno
  • Androidlic Forum
No Result
View All Result
Androidlic
No Result
View All Result
Home Android police

Smart TV tech loophole allowed miscreants to view private YouTube videos

by admin
April 6, 2021
in Android police
0
Smart TV tech loophole allowed miscreants to view private YouTube videos
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT


Safety researcher earns $6,000 bug bounty for pondering outdoors of the field

Smart TV web security flaw allowed miscreants to view private YouTube videos

ADVERTISEMENT

A safety researcher earned a $6,000 bug bounty after uncovering a set of internet safety flaws that allowed attackers to play supposedly personal YouTube movies.

David Schütz (@xdavidhu) reported the privateness weaknesses to YouTube’s father or mother firm Google, which acted promptly to shore up safety controls after verifying the issue final July.

This cleared the way in which for Schütz to supply an in depth technical write-up on the privacy-related situation, which he printed on Monday (April 5).

Distant management

Schütz first started exploring the difficulty some years in the past after noticing the YouTube app on his Android cellphone gave him the choice of enjoying personal movies on a buddy’s internet-connected smart television.

The researcher wasn’t signed into the TV on the time – an element that later inspired Schütz to discover how the expertise labored after he had joined Google’s Vulnerability Reward Program.

The YouTube for Android TV App is, because it transpired, is actually an internet site moderately than a posh Android software. Schütz found that the expertise hundreds content material in a WebView-like browser, referred to as Cobalt.

RELATED Details of YouTube viewing history exposure bug made public

After altering the Consumer-Agent header on his PC-based browser to Cobalt, Schütz was capable of get on the YouTube TV app and start testing.

On the time, customers have been capable of management a TV through the desktop YouTube website, even when they have been on a special community. This function has subsequently been faraway from the consumer interface, in line with Schütz.

After pairing an emulated sensible TV with one other browser operating on a PC, Schütz found that he had the choice of enjoying personal YouTube movies on the tv.

This setup allowed Schütz to look at the pairing course of between a cellular system and a wise TV, permitting the researcher to uncover some fascinating conduct within the course of.

Going to the polls

After beginning the pairing course of, the TV switches right into a ‘polling’ mode, which is kind of a typical factor at Google.

As a substitute of WebSockets, Google often makes use of these bind requests, that are principally HTTP requests that take very lengthy if there are not any new occasions however return instantly if there are some. And the TV calls this /bind endpoint again and again.

Read more of the latest security research from around the world

Analyzing how this course of labored allowed the researcher to determine that Google was utilizing an additional video-specific token, referred to as ‘ctt’, to be able to allow a consumer to play personal YouTube movies:

When the consumer requests to play a personal video, the occasion the TV receives from the /bind endpoint contains an additional ctt parameter subsequent to the videoId.

When enjoying the video, the TV then requests the uncooked video URL from the /get_video_info endpoint and contains the ctt token as a GET parameter named vtt (for some motive).

With out the ctt token, the TV can’t watch the personal video.

This ctt token supposedly solely offers permission to look at that particular video moderately than every other personal video.

After analyzing the method utilizing Burp Suite, Schütz uncovered an internet safety flaw on this “distant management” expertise involving a POST request to a /bind endpoint.

“Because of a lacking CSRF [cross-sire request forgery] safety within the YouTube Lounge API (an API for distant controlling YouTube TVs), a malicious web site may management/ship instructions to YouTube TVs, within the title of the sufferer who visited the web site,” Schütz instructed The Each day Swig.

Exterior the field

Left unaddressed, the flaw a way for an attacker to view and/or movies marked as personal on YouTube after solely a minimal quantity of social engineering trickery.

Schütz defined: “An attacker may have arrange an evil TV, and utilizing a malicious web site, instruct the sufferer’s browser to play all the sufferer’s YouTube movies on the attacker’s evil TV, thereby stealing all the sufferer’s personal and unlisted movies.”

To be able to repair the flaw, Google made adjustments in order that the /bind endpoint now requires an Authorization header with an OAuth Bearer token to be authenticated, in line with Schütz.

DON’T FORGET TO READ Google awards researcher $133,337 top prize in cloud security competition

Earlier than the flaw was resolved, an attacker may have stolen all private and unlisted movies from a sufferer (and even the contents of personal playlists such because the ‘Watch Later’ checklist), just by engaging them to open a malicious web site.

All a sufferer would wish to do would have been to trick a sufferer into clicking a hyperlink whereas signed into YouTube, in line with Schütz.

The Each day Swig invited Google to touch upon Schütz’s analysis. No phrase as but, however we’ll replace this story as and when extra data comes at hand.

READ MORE Bug Bounty Radar // The latest bug bounty programs for April 2021





Source link

ShareTweetShare
ADVERTISEMENT

Related Posts

The Redmi K40 will be a gaming phone too, with 300+ Hz touch sampling rate and gaming accessories
Android police

Samsung, Xiaomi, Oppo, vivo, ZTE to launch phones with under-display cameras this year

April 20, 2021
UK invokes national security to probe Nvidia’s ARM deal, Telecom News, ET Telecom
Android police

UK invokes national security to probe Nvidia’s ARM deal, Telecom News, ET Telecom

April 20, 2021
Nokia to slash up to 10,000 jobs in race to ring up 5G network sales, Companies & Markets News & Top Stories
Android police

Fending off bugs that may affect 100m Internet-connected devices, Tech News News & Top Stories

April 20, 2021
WhatsApp Pink is a virus, not an app makeover — what to do if you get a link
Android police

WhatsApp Pink is a virus, not an app makeover — what to do if you get a link

April 20, 2021
F-Secure Total For Mac Review
Android police

F-Secure Total For Mac Review

April 19, 2021
Hey Google, find my iPhone! Google Assistant’s new trick scales the wall with Apple
Android police

Hey Google, find my iPhone! Google Assistant’s new trick scales the wall with Apple

April 19, 2021
Next Post
OnePlus 9, OnePlus 9 Pro Getting OxygenOS 11.2.3.3 Update in India With Camera, Battery Life Improvements

OnePlus 9, OnePlus 9 Pro Getting OxygenOS 11.2.3.3 Update in India With Camera, Battery Life Improvements

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

HTC Desire 12s With 5.7-Inch HD+ Display Launched: Price, Specifications

HTC Desire 12s With 5.7-Inch HD+ Display Launched: Price, Specifications

March 21, 2021
Android Recognizes ioXt Alliance Certification Program – Yahoo Finance

Android Recognizes ioXt Alliance Certification Program – Yahoo Finance

February 22, 2021
Echo reader bags Samsung phone and Kindle in competition win

Echo reader bags Samsung phone and Kindle in competition win

March 7, 2021
Upstox alerts users of data breach

Upstox alerts users of data breach

April 11, 2021
Samsung Galaxy F41 to Launch in India on October 8 – Check Specifications, Expected Price, and Other Details

Samsung Galaxy F41 to Launch in India on October 8 – Check Specifications, Expected Price, and Other Details

April 14, 2021
Samsung Releases Android Security Patch April 2021 For Its Devices Before Others – Research Snipers

Samsung Releases Android Security Patch April 2021 For Its Devices Before Others – Research Snipers

March 29, 2021

Recent News

Byron Allen Launches Free Streaming Service ‘Local Now’ Delivering Local News and Premium Content

Byron Allen Launches Free Streaming Service ‘Local Now’ Delivering Local News and Premium Content

April 20, 2021
5 months on, panel fails to reach consensus : The Tribune India

5 months on, panel fails to reach consensus : The Tribune India

April 20, 2021
Best HTC Phones Under 5000 in India ( 20 April 2021 )

Best HTC Phones Under 5000 in India ( 20 April 2021 )

April 20, 2021

Categories

  • Android apk
  • Android Mobile
  • Android police
  • Android Tablets
  • Android tv
  • Android watches
  • HTC Mobiles
  • Huawei
  • Infinix
  • LG Mobiles
  • Nokia
  • Smartphones
  • Sony Tablets
  • Tablets
  • Techno

Contact Us

  • About
  • Privacy Policy
  • Terms
  • Advertise
  • contact us

© 2021 Androidlic .

No Result
View All Result
  • Home
  • Android Mobile
  • Android apk
  • Android Tablets
  • Android police
  • Android TV
  • Android watches
  • More
    • HTC Mobiles
    • Huawei
    • Infinix
    • LG Mobiles
    • Nokia
    • Smartphones
    • Sony Tablets
    • Tablets
    • Techno
  • Androidlic Forum

© 2021 Androidlic .

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

SAVE & ACCEPT