Youtube Fun
May 3, 2007 on 1:34 pm | In Blackhat SEO |A good few months back I was playing around with youtube and within a very short time I found a little way to have some fun with it. I didn’t intend to publish it but since someone else I spoke to about this has decided to go further with it and ignore me I’m going to throw it out there.
Go into your account settings on youtube and then click on channel design. You will see a box where you can enter a background image URL. In there you can actually enter any url which will be executed whenever someone views your channels home page. Although it needs to end in a valid image format. For example you couldn’t use the url http://www.onlinehoster.com/blog/index.php but you can use the url http://www.onlinehoster.com/blog/index.php?gif which will essentially do the exact same thing! For example you could make it so that if someone viewed the page they would automatically be subscribed to your channel without even knowing so by using the URL http://www.youtube.com/subscription_center?add_user=youtube-username&gif
There are so many things you can do with this so lets see how long before we see a nice youtube worm spreading :p
9 Comments »
RSS feed for comments on this post. TrackBack URI
Leave a comment



[…] has a Digg story about his Youtube exploit - I have seen it in action and it works very well..read more | digg […]
Pingback by www.seoidiot.com » Blog Archive » Youtube WORM - Exploited! — 4th May, 2007 #
Wouldn’t http://www.youtube.com/subscription_center?add_user=youtube-username&gif be a more sensible URL?
Cheers though.
Comment by Robin Haswell — 4th May, 2007 #
[…] aparut un exploit pentru YouTube la Esrun pe blog care permite abonarea automata la o pagina de catre cei care o acceseaza. Postul e scris […]
Pingback by Exploit YouTube | Bani pe net - by Cotiso — 4th May, 2007 #
Probably Rob, post updated
Comment by admin — 4th May, 2007 #
[…] Cross-Site-Scripting ist niemand sicher - nicht einmal Google. Wie im Blackhat SEO Blog nachzu lesen ist, gibt es eine Reihe von Lücken auf der YouTube-Seite. Zum Beispiel kann man […]
Pingback by CHIP Online 0-security blog » Blog Archiv » Springt der MySpace-Wurm zu YouTube über? — 4th May, 2007 #
[…] Blackhat SEO - Esrun » Youtube Fun There’s an online exploit of YouTube’s channel background that enables you to automatically subscribe anyone who visits the page. There’s no danger to the end user, but it is a little sinister! (tags: youtube channel subscribe hack) […]
Pingback by links for 2007-05-04 | The Marketing Technology Blog — 4th May, 2007 #
[…] Cross-Site-Scripting ist niemand sicher - nicht einmal Google. Wie im Blackhat SEO Blog nachzu lesen ist, gibt es eine Reihe von Lücken auf der YouTube-Seite. Zum Beispiel kann man […]
Pingback by 0-security-blog » Blog Archiv » Springt der MySpace-Wurm zu YouTube über? — 18th May, 2007 #
http://www.youtube.com/subscription_center?add_user=youtube-username&gif
doesn’t work. it says ‘enter a valid image url’
Comment by lkdfj — 22nd May, 2007 #
I checked this out yesterday after an email and it would appear that it has been patched up. That’s what happens when something gets posted on this site I’m afraid.
I didn’t spend more than 2 minutes checking it out so it could still be working with a little modification.
I’m sure if you played around you could get something similar working
Comment by admin — 22nd May, 2007 #