YouTube hijacked for Storm worm spam

By Liam Tung on 08 October 2007

Tags: marshal | sophos | spam | storm | trojan | youtube | exploit

Spammers are exploiting YouTube's "Invite your Friends" facility to send spam containing a Storm Trojan from the video sharing site.

Bradley Anstis, director of product management at security firm Marshal, said that YouTube users can invite their friends to view videos that they are looking at or have posted. Using the facility gives them the opportunity to e-mail any address from their account -- a feature the spammers are now exploiting.

The YouTube scam is targeting Xbox owners, urging recipients to collect a prize version of the popular game Halo 3. Anstis said clicking on the link to "winhalo3" leads to a file containing a Storm Trojan.

To date, Marshal has tracked around 150,000 of the spam e-mails thought to have originated from YouTube accounts.

The e-mails are exploiting a vulnerability in the sign-up process, according to Marshal, which reported in August a Trojan designed to generate large numbers of Hotmail and Gmail accounts. A similar vulnerability is being exploited in the case of YouTube, said Anstis, adding that spammers have used Intelligent Character Recognition (ICR) software to circumvent the verification system commonly known as Captcha. The Captcha system -- where a user must read and re-enter a selection of blurred or unevenly spaced text and numbers into a box before being issued a new account -- is used make it harder for software programs, rather than genuine users, to sign up for services

"There are ways of subverting those sort of systems," he said. "Service providers need to look at how to prevent that from happening."

The YouTube Help Centre also advises users to exclude the service@youtube.com e-mail address from spam filtering lists -- a fact Anstis said spammers are likely aware of.

Security vendor Sophos has also reported the YouTube spam problem. Senior technology consultant for the company, Graham Cluley, said this case differs to the technique commonly associated with the Storm worm, which typically targets personal PCs for the job of sending spam.

According to Cluley, the YouTube spamming marks a departure for the junk e-mailers -- instead of using botnets to distribute spam, they can use a familiar Web site to pass on messages.

Marshal's Anstis said this scam could herald the rise of outsourced bot-herding whereby the botnet controller pays a third party to acquire further bots.

"Now, you can rent time on a botnet network and have a tech support department. If I'm spammer, I would just rent time on a botnet which includes tech support from the botnet owner and a massive resource pool with huge amounts of bandwidth. This may be a third business -- selling services to the Trojan operators to help expand their networks. For example, if I own a Trojan network, I pay you 20 cents per bot you get me," he noted.

Like this article? Click below to send it to your mobile for free!

<a href=http://www.allwebhostingresources.com>cheap web hosting</a>
22/03/2008 08:15 AM

very interested if this happened. Best wishes for youtube about this hijacked

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Silent Hill: Homecoming banned in Australia

  • Rugby League 2: World Cup Edition announced

  • Rock Band coming to Australia

  • Report: Nintendo to make $1.6 million profit per employee

  • Sony launches Life with PlayStation

  • EA execs on Aussie Rock Band delays

  • Mercenaries 2: World in Flames

  • Hands-on with the Guitar Hero World Tour instruments

  • Lego Star Wars: The Complete Saga

More articles »

Find the right game

Brand
  • Multiple options can be selected

    • Mercenaries 2: World in Flames

      Mercenaries 2: World in Flames

      Broken, buggy, and shallow gameplay leaves Mercenaries 2's world in flames.

    • Lego Star Wars: The Complete Saga

      Lego Star Wars: The Complete Saga

      Even if the new bells and whistles aren't enough to bring back established fans, this is still Lego Star Wars at its finest.

    • Too Human

      Too Human

      Too Human is a game of false starts and unrealised potential that infiltrate almost every aspect of the game. This action/role-playing hybrid is too unbalanced and too frustrating to recommend.

    • Madden NFL 09

      Madden NFL 09

      A few key gameplay additions and enhancements make this year's Madden great despite some unseemly flaws.

    • Braid

      Braid

      A moving story, serene visuals, and brilliant puzzles make Braid an adventure that you absolutely should experience.

    More reviews »

    Membership benefits

    Create a personalised homepage

    Create a personalised homepage

    Choose your interests from our 16 categories and only see articles relevant to you. Sign up for a free CNET.com.au membership now!