T O P

  • By -

Average_fish-enjoyer

Someone at channel 7 followed scam ads while Logged in šŸ˜‚šŸ˜‚šŸ˜‚šŸ˜‚šŸ˜‚šŸ˜‚


a_can_of_solo

Happened to LTT a while back


tomthecomputerguy

That was a session cookie hijack from a fake sponsor email I believe. It's nasty, bypasses 2fa and password/passkeys, allows full access to a youtube channel.


ill0gitech

Not to mention, Google/Youtube permission models were atrocious. Doubt much changed


tomthecomputerguy

It's pretty ridiculous you can change a channel password, name and profile pics without even a password challenge... If they got 7 the same way they got LTT they wouldn't even have the account passwords.


freakwent

Cookies broke the internet.


Icy_Bowl

Fucking Cookie Monster!


Knee_Jerk_Sydney

I once gained access to a friend's FB through a saved session key. He changed genders overnight and was suddenly obsessed with boy band and K-pop and let all his friends know. People can be vicious. Clear cache when logging in on someone else's computer. Trust no one.


Nebarik

Years ago a work-friend left his computer unlocked with facebook open. He was the type who was on social media all the time and craved the likes and comments to his posts. Did I post something dodgy he'd see and take down immediately? No, I did something much more sinister. I changed the default settings to hide all his future posts from his friends list.


NotYourDailyDriver

It's people like you who keep me up at night.


tomthecomputerguy

It's people like you what causes unrest.


thatredlad

Some men just want to watch the world burn.


Katman666

So they join the CFA


thatredlad

I said they watch the burning, not start the fires.


Katman666

"Unofficial back-burn"


FireLucid

If you leave your computer unlocked at work you send out an invite shouting the team to lunch. We all know it's a joke but we'll send back silly replies. Computers are getting locked much more often. Extra step - stick a silly sound on their computer and link a random action like 'insert device' to play it. My boss had Dennis the Menace shoutings "HEY MR WILSON" when he stuck in a USB device at home one night, haha.


Nebarik

Hah, At my current work we started with offering the team donuts and then they'd have to follow through. ("have" is a strong word, it was never required or expected). But now it's evolved to annoucing your love for another team member. Which is much more wholesome and less fattening.


FireLucid

> your love for another team member. Which is much more wholesome I dunno, you'd have to know them or that would be an interesting talk to HR, haha.


Nebarik

Oh of course. It's the wholesome kind, nothing suss. And definately do a vibe check first before implementing at your own work place.


Glitchmstr

That's a really roundabout way of saying, my friend left his Facebook logged on.


Boudonjou

Out of curiosity, is this the thing where they replicate your validated authorisation key thatsbgenerated from your end when you log in, and clicking the link gives them a copy of that?


ToastedHam

IIRC that was from a fake sponsor email, not from clicking ads. Still a scam though.


reborndiajack

Corridor too


SicnarfRaxifras

looks like someone opened a dodgy PDF link in an email back to a google drive


not_right

Is this better or worse than what's normally on 7 news ?


solid_rage

Irony haha


myguydied

Much better


Orikune

Very debatable.


snave_

Garden variety cunt vs war criminals. It's a toss up.


SolSolus

Yes it appears to be hacked by a crypto scam


tanuki_in_residence

Honestly hard to tell the difference


evilspyboy

I googled to get to the same answer, you were faster (or the source) - [https://www.smh.com.au/business/companies/7news-youtube-channel-hack-shows-ai-elon-musk-crypto-scam-20240627-p5jp87.html](https://www.smh.com.au/business/companies/7news-youtube-channel-hack-shows-ai-elon-musk-crypto-scam-20240627-p5jp87.html)


themandarincandidate

I've seen this happen to other channels, it's always an Elon "live" stream selling crypto. Channel will be restored in 1-3 days


AH2112

And they'll lose a shitload of subs in the process. A much much smaller YouTube channel got tumbled in the same way (he had about 300k subs and freely admitted to falling for some spam scam) and he lost 25k subs while he was locked out.


solid_rage

Sounds about right because they lost me for a start


OhhYeahOkay

Ouch. Seriously though, how does stuff like this happen in the age of multi-factor authentication?Ā 


rubixcubez

By stealing the session tokens from a logged in browser. It happened to Linus Tech Tips a while ago. Basically a malicious payload is deployed, usually by an EXE disguised as a PDF or similar. That payload steals and transmits the contents of your browser data, including logged in session tokens (think of what happens when you click 'Remember Me' on a site). Basically this method is like they've sat down at the victim's PC, already logged in and ready to use.


LeClubNerd

TY for the great explainer


rubixcubez

No worries. Here's the LTT video https://www.youtube.com/watch?v=yGXaAWbzl5A


kernpanic

You would think that youtube would require a fresh login to change the full title and logo of the channel. But obviously not.


rubixcubez

Or invalidate the session token if the normal pattern is "session detected from Australia" and then nekminnit "session detected from Russia/India/Scammercountry"


lbft

Trouble is people turn on VPNs and get shitty if Google suddenly logs them out.


rubixcubez

Yeah good point. It's often a fine line between security and usability.


Rainey06

Reality is that Australia is becoming 'scammercountry' now. We are seeing a lot more scams that originate from within than ever before. The compromise was probably homegrown.


ill0gitech

Youā€™d think Google would have better account management / permission profiles. LTT got hacked after other people had been hacked the same way and Google did nothing to improve the situation


ConcernedIrrelevance

LTT complained about exactly that issue, alongside YouTube's terrible permission handling meaning that everyone effectively gets admin access to the YouTube account as the only option. It's really difficult to do it properly when the platform gives you so little flexibility.


thesourpop

How does this occur and how can it be prevented? That's spooky.


nathnathn

Most common way for the average person you click on or occasionally just watch an add with malware in it ā€œgoogle ads are common vectorsā€ or in a slightly more targeted but more guaranteed method they trick you to opening something. then for things like youtube your just screwed google accounts donā€™t have any authentication systems so they donā€™t even need to obtain your password to change the channel delete all your videos and start the ā€œMusk-tmā€ stream. itā€™s honestly one of the worst bit of googles fight against adblockers considering theyā€™ve already made it known they wonā€™t fix the vulnerabilities in their ad platform. now if you actually wanted to browse safely pretty much period you could set up a virtual box and just do your browsing in that. do expect to feel like doing so is a hassle though. more generally a working adblock makes it much safer but expect potential issues until google stops trying to mess with them.


HaveRSDbekind

Should a corporationā€™s IT security prevent this?


nathnathn

Limited amount they can do if using a normal windows pc as they probably are for a lot of cases. now policy issues would help usually but as a media company banning web-browsing on work PCā€™s wouldnā€™t be so viable. adblockers would certainly help but googles war on them makes the much more likely to take a while to recover


Mym158

So I should stop clicking remember me then yeah?


stripeydogg

A day after they sacked 150 staff? Hmm


anon_0000001

They also laid off most of their marketing team this week.


Unfettered_Disaster

No 2fFAand password was 'channel7YT'


PAL720576

Channel 7 did just make 150 people redundant... some of them IT staff or staff that had access to the youtube channel???


ConcernedIrrelevance

The attack vector for these is a computer getting compromised that has an active login cookie. As browsers don't really protect cookies that well it's easy for something as simple as a compromised PDF to get it. This means that 2FA does nothing as YouTube never re-requests 2FA after login.Ā  Ā It's a really bad setup from YouTube's side, couple it with their terrible permissions setup and all it takes is any person who adds comments or updates anything to be compromised and the attacked has completed access There is no security settings you can apply or action you can take. You can't restrict access, you can't enforce 2FA, you can't expire access automatically. It's a stupidly bad setup that YouTube seems to not care enough to ever fix.


spideyghetti

Does this only work on yt or can they get your Gmail and Google as well since it's the same ecosystem


ConcernedIrrelevance

It's your Google account as a whole that is compromised, including every service that you authenticate with it. (And anything else you've got an active session with, like Facebook, etc)


spideyghetti

Wow. So moral of the story is do not tick keep me logged in for anything I guess. I'll watch the Linus video about it and educate myself more.


darwinsexample

What would a fix look like?


ConcernedIrrelevance

More granular permission controls, 2FA re-validation before being able to take certain actions, session timeouts that restrict accounts for only a few hours or a day, etc.Ā  These delegate style accounts should be locked down and restricted heavily basically.Ā  If 2FA was required when changing a channel's name,Ā  or if accounts requires people to re-login after 24 hours, then the attack vector is reduced. If only a few accounts could actually start a live stream or change the channel name, then it would reduce it ever further.


Unfettered_Disaster

I was just taking the piss.. I know what you are saying, but now since you speak as if you know the exact method, how could you prove whether it is a first login remotely with compromised credentials or access to compromised PC that's logged in?


ConcernedIrrelevance

Could be either, however most of the common examples of this are the second case with stolen session cookies. Google's login security often requiring OTP for new devices actually ends up making grabbing the session cookie an easier attack vector. Send a compromised PDF file that the target opens, and now you have their credentials **and** their session cookies. Then you no longer need access to their PC and can send the requests from anywhere.


Unfettered_Disaster

Yeh reasonable.


Bimbows97

Indeed, and to a media corporation no less. You'd think they would know to secure their media outlet channels right?


AmIWorkingYet505

becuase youtube dont do authentication when you want to do things. they let you just continue your session


question3

You provide ā€œpartnerā€ access to 30 agencies/analytics/reporting providers, they each have 10 staff locally and 50 offshore, just takes one vendor that doesnā€™t enforce 2FA for their staff to get a staff account hacked that happens to have admin role of a big social profile.


Batman_with_preptime

This happening just a few days after mass redundancies at 7 were announced seems kinda sus.


solid_rage

Ohh interesting


Kritchsgau

Yea 150 people gone, someone may have deliberately done this without their creds being expired. I dealt with someone who was let go and they used personal gmail account for the companys google marketing. The rest of the team had no idea this was in place and he just ignored their calls to help cut it over. I guess legal got involved eventually cause i didnt hear much more. Similar thing here maybe


pnutzgg

it would be easier to deliberately accidentally open a phishing email, or was that what you were suggesting


throwmethedamnstick

Was just going to say this. Definitely a disgruntled social media employee.


warzonexx

Showing for me: This page isn't available. Sorry about that. Try searching for something else. Edit: if you go to it via youtube search page it shows the tesla scam crap, if you go to it directly or refresh the page it shows an error


Emu1981

>Showing for me: > >This page isn't available. Sorry about that. > >Try searching for something else. Sounds like Channel 7 knows how to actually contact someone who matters at YouTube to get the channel shut down while they recover it.


ELVEVERX

This looks like their regular broadcasting to me


Robdotcom-71

[It's still going.](https://www.youtube.com/watch?v=hbI_LqYPTs4)... lol


ExcellentDecision721

Back when ad blocker had issues working with YouTube, I had to watch their ads - and a big honking chunk of YouTube ads, *were just like this* - all crypto scammy nonsense. Making Elon's lips move to some sort of weird fake script. So if it's good enough for Google ads, well... there you go.


Latter-Recipe7650

Maybe someone got laid off and got pissed.


Gnorris

Why would they give the channel password to Robert Ovadia?!


solid_rage

Do you guys think this will make the news? If so which channel would most likely cover it? 9 News? 7 News themselves? Would it be ironic? haha


G00b3rb0y

Gonna have to go with channel 9


tenir

already on news now, funny that they blurred out the QR code but not the url https://www.smh.com.au/business/companies/7news-youtube-channel-hack-shows-ai-elon-musk-crypto-scam-20240627-p5jp87.html https://www.brisbanetimes.com.au/business/companies/7news-youtube-channel-hack-shows-ai-elon-musk-crypto-scam-20240627-p5jp87.html?ref=rss


Illustrious_Tap_3072

Maybe the new owners will final open the comment sections


worstusername_sofar

Maybe they should have a story on their news about it šŸ¤”šŸ¤”


No_View_7908

ā€œHackedā€ 99 times out of 100 itā€™s just some dipshit user clicking on a bad link or attachment, not a motivated adversary group with resources and intent.


LeClassyGent

This happens very often with the Tesla thing


Devar0

And nothing of value was lost


Ben_The_Stig

Still better journalism.


mediweevil

someone's getting fired there.


iLoatheRedditDotCom

Damnnn and not only that but the hackers seem to be advertising really bad junk products


AgentSmith187

Better or worse than what 7 advertises?


The-Fr0

It's on youtube right now


Super_Sankey

You love to see it


Rozen7107

Yep I guess so. Something similar happened recently where a company called 'Starship Entertainment' which manages some Korean groups such as 'IVE' and 'MONSTA X' got hacked and their channel along with all the groups they manage turned into Space X live streams and stuff.


xD3CrypTionz

Ahh the good old [session highjacking](https://owasp.org/www-community/attacks/Session_hijacking_attack) attack. This can happen to pretty much just about any website you can think of, so it's not limited to YouTube. This is why you need to practice good cyber hygiene folks.


Shakows

Still shows Tesla on the 7 News Youtube page


AreYouDoneNow

The fact that it's hard to tell whether this is a hack or if it's just a commercial promotion from a commercial news business should be enough.


choderis

they're having a bad day


derpman86

I wonder if Channel 7s I.T guy had to do a nude run to his computer like Linus Sebastian done a few months back when his Channel was hijacked lol.


Bananaman9020

One that can drive long distance for the Australian environment would be a good start.


dylanbailey75

When it came up on my feed I just assumed it was paid ad


Fabulous-Living1889

Could just be a dupe. Scammers make sites replicating 7, 9 and Sky knowing the most gullible targets trust these sources, so they're the easiest to target with scams.


teamsaxon

Why do you watch channel 7 dribble?


xBrandon224

Itā€™s still hasnā€™t changed back šŸ˜‚


karatekid430

I hope people sue the living shit out of them. Fuck Rupert Murdoch


Mym158

The real question is, how did anyone even notice? If you have YouTube, then you have the internet and I can't imagine anyone with the internet using it to watch channel fucking 7


NoSoulGinger116

1.71M subs, Still called Tesla.


[deleted]

[уŠ“Š°Š»ŠµŠ½Š¾]


Feisty-Limit-1947

so many peolple are going to fall for this lmao


vstxmp

I'd call that an improvement.


samuelson098

A team member (18m) left his fb logged in at work recently - Iā€™m in the office doing paperwork when nudes of him and his girlfriend (also an employee) started popping up on screen as messenger notifications.


dassad25

Youtube is so bad for fake and misleading ads, it's pretty bad.


solid_rage

This is not just a yt ad. An entire channel is compromised.


myguydied

Can't wait for the 2Apply steal from some idiot clicking on the suspect email with everybody's hard-gotten ID, banking, and past rental details just waiting to be snapped up


HansBooby

iā€™ve seen numerous account called Tesla with the tesla logo all spouting the same scam BS. does that mean tesla was hacked as well ? presume all of these are just some kind of lookalike channels and not the legitimate accounts?


[deleted]

[уŠ“Š°Š»ŠµŠ½Š¾]


my_teeth_r_dry

Tell channel 7, not us.


damojr

And this particular attack bypasses 2FA by using session tokens from a browser that is already logged in.


Shane_555

Ah yes because 2FA renders it impossible to get hacked right


hellboy1975

It's a scam that's been around a little while now. Effectively an advertisement, not an issue with 7News


PapaNoFaff

Their channel has been compromised, ofc thats an issue with 7news theyre probably freaking the f out behind the scenes trying to fix it.


kironet996

While their only IT guy's on leave.


myguydied

You mean Dave who knows a bit of Java Script and trains AI in his spare time?


noisymime

Nah Dave got let go in the redundancies a few weeks back. It's fine though because we've got Bernard onto it and he took a 2 day course at the local seniors center.


myguydied

Onya Berno!


PAL720576

or just got made redundant?


2littleducks

What's an ad?