
A 22-year-old programmer and security researcher from Kazan Kamil Hismatullin discovered a vulnerability in YouTube, which allowed him to remove any video on the service, writes TJ . He described the details of this story in his blog .
According to Khismatullin, some time ago, he received a letter from Google with an invitation to take part in the program called VulnerabsHet Research Grants. Within the framework of this program, the company pays a small advance payment to specialists in the field of information security (Khismatullin received $ 1337) in the expectation that they will study Google products for vulnerabilities. If an error is found in a particular product, the expert receives the main reward.
Khismatullin decided to study the YouTube Creator Studio application, designed for owners of channels on YouTube. Using this application, you can manage uploaded videos, respond to comments and analyze statistics.
As the programmer wrote, in just a couple of hours of work, he had two reports for Google. So, in the video broadcasting system, Khismatullin found a logical mistake that allowed you to remove through an appeal to YouTube Creator Studio any video on the service, using only tokens of its session as an authorization key.
Having discovered this vulnerability, the programmer recorded a demonstration video. From the video it follows that he managed to remove the video from his channel without authorization.
Hismatullin did not specify what information was contained in the second report. He also noted that all the work took him about six to seven hours. At the same time, he spent two hours on the fight against the desire to delete all the notes from the channel of the famous musician Justin Bieber.
When Khismatullin sent a report on the found vulnerability in Google, the United States was an early morning. Nevertheless, the answer came very quickly, since the discovered bug was a serious danger.
As a result, the vulnerability was eliminated, and the company paid the Russian expert a prize in the amount of five thousand dollars. One of the commentators on the Hismatullin blog considered this amount more than modest. Khismatullin admitted his rightness and noted that he hoped to get 15-20 thousand and even wanted to file a complaint with Google. However, having studied the rules of the Vulnerably Research Grants program, the company has concluded that the company has listed it the most possible reward.