company logo

Product

Our Product

We are Reshaping the way Developers find and fix vulnerabilities before they get exploited.

Solutions

By Industry

BFSI

Healthcare

Education

IT & Telecom

Government

By Role

CISO

Application Security Engineer

DevsecOps Engineer

IT Manager

Resources

Resource Library

Get actionable insight straight from our threat Intel lab to keep you informed about the ever-changing Threat landscape.

Subscribe to Our Weekly Threat Digest

Company

Contact Us

Have queries, feedback or prospects? Get in touch and we shall be with you shortly.

loading..
loading..
loading..
Loading...

Vid.me

Supply Chain Attack

Domain Name System

loading..
loading..
loading..

Vid.me- a misconfigured defunct video hosting platform is dumping Porn videos on major news websites

A Non-operational platform is dumping porn videos on news websites. The domain name for the old site was changed along with the content in the HTML <iframe>s......

24-Jul-2021
3 min read

A non-operational video hosting website used by sites that publish news to inline videos in their articles injected porn videos in some pages of significant news publishers like The Washington Post and New York Magazine.

Vid.me - a site that hosted user-submitted videos allowed other websites to embed their videos in their coverage. In 2017, Vid.me shut down its businesses and bought another video hosting platform Giphy. The domain was updated to a new NSFW website - 5 Star HD Porn. According to its WHOIS ** records, it happened at the start of this month.

First reported by a Twitter user @dox_gay, hardcore porn is now embedded on the web pages of Huffington Post, New York magazine, The Washington Post, and a group of other sites. This incident happened after 5 Star Porn HD bought the domain for Vid.me.

All the embeds from Vid.me on any website that displayed thumbnails and links of X-rated material now redirect to the homepage of the 5 Star Porn HD website. Many of the above-mentioned news publishers immediately tried to take down the adults-only Vid.me iframe s.

BeFunky-collage BeFunky-collage

As reported by vice, this is a significant problem, and unfortunately, it points to a much bigger problem: "The internet is a collaborative hallucination that is fading away." This incident is a good reminder to always third-party inline content at your risk. The content present in the iframe s can change drastically within a short span.

vidme-iframe_copy_677x350