In his own words:
"This is basically a google dork. What basically happens is that if someone is logged in to his/her FTP account and checks a page which embeds a YouTube video through the FTP client, YouTube will register that as a hit from "username
Which means that you are going to get his login information to his FTP server. Enjoy!
site:youtube.com "clicks from ftp @""
Which is a pretty cool find. But does anybody see the irony in this? I certainly do!
Original Thread:
http://www.w4ck1ng.com/board/showthread.php/new-youtube-exploit-ftp-5521.html
1 comment:
Silentz!
It is very interesting bug in Google. Nice find by Lyecdevf.
And it's ironically that Google help bad guys to find ftp credentials of Youtube (i.e. their own) users. Like it is ironically to use Google to quickly find sites with holes in Google Custom Search Engine (MOSEB-15 Bonus: Vulnerability in Google Custom Search Engine (http://websecurity.com.ua/1050/) ;-).
Post a Comment