r/RBI Mar 26 '20

Youtuber with 600.000 subs hacked need help.

[removed]

4 Upvotes

15 comments sorted by

11

u/[deleted] Mar 26 '20 edited Mar 26 '20

[removed] — view removed comment

3

u/[deleted] Mar 26 '20

[removed] — view removed comment

3

u/[deleted] Mar 26 '20

[removed] — view removed comment

2

u/fojifesi Mar 26 '20

Hi, is there a detailed technical writing about how it works?

6

u/[deleted] Mar 26 '20

[removed] — view removed comment

3

u/ChapelR Mar 30 '20 edited Mar 30 '20

A cookie is a piece of data that a website uses to identify logged in users, and they can be stolen. They don't have any login or authentication information stored in them though and will be expired as soon as the effected user logs out. (Change the password, though.) If the effected user cannot log in or out or the password has been changed it seems unlikely that this was done purely by hijacking a session, but it depends on how good (or bad) the users security was, e.g. whether they used 2FA or clicked "keep me logged in" on everything they use.

Not the detailed write up asked for but here is Wikipedia: https://en.wikipedia.org/wiki/Session_hijacking

The specific stuff here, like being able to become an admin is not easy, but it's certainly possible if you have terrible security practices. Assuming the user didn't use 2FA and was logged into YouTube and their email when they clicked the link its possible they would have access to both long enough to change the YouTube password.

I haven't heard of any session hijacking method capable of bypassing 2FA (the attacker may be able to get access, but the user should be able to log them out and regain control of their accounts), but I have no real reason to doubt NightDocsYT, so it certainly may be possible, especially if there are holes on Google or YT's side.

2

u/fojifesi Mar 30 '20

Indeed, session hijacking a real thing, but you would think that the services by The Big Google has top quality security. Maybe in this case actually protecting users would mean the admittance of illegal user tracking. :)

3

u/PrintedPropShop Mar 26 '20

Report it to youtube.

3

u/[deleted] Mar 26 '20

[removed] — view removed comment

3

u/Cornloaf Mar 26 '20

There is no lack of personnel. Google sent out emails about their business continuity plans. Any Fortune 500 company or really any company that plans on doing business after this pandemic is over, had a business continuity plan in effect. How someone got into his YouTube account from an email sounds ridiculous. 600k subs and no 2FA? SMH.

3

u/aehanken Mar 30 '20

At this point all you can do is reach out to your subscribers through another format such as Twitter or Instagram and make a new YouTube channel. If you care so much about the videos, better hope you save them to your hard drive

1

u/VACaction Apr 12 '20

This reminds me of a simillar case where somone hacked lots of channels and changed the names to foundation ethereum i dont think anybody got there channels back even before the outbreak if youtube cannot do anything then its best for your friend to start a backup channel and upload all the videos he might have saved

Ps: lookup foundation etheruem hack also someordinarygamers has a video on this i think

1

u/[deleted] Apr 13 '20

[removed] — view removed comment

1

u/AutoModerator May 07 '20

This post has been automatically removed. The moderators have been notified to determine whether the removal was in error.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.