RedTube Fixes Malware Security Breach

BURBANK, Calif. — RedTube announced this week via Twitter that it fixed a bug on its adult tube site that redirected users to malicious URLs and exposed them to Trojan horse viruses.

The highly trafficked MindGeek-owned property apparently was hacked via a malicious HTML iframe placed directly in the source code of the site and made invisible to the user.

The source code on RedTube's main page was modified in order to redirect the user to malicious URLs hosting the Angler Exploit Kit, according to security blog MalwareBytes, which first discovered and reported the breach. 

Once redirected, the software kicks in and tries to exploit Adobe's recently patched CVE-2015-0313 bug to run malicious code, MalwareBytes said.

Officials of MindGeek’s RedTube division, in a response to MalwareBytes, said that the attack occurred this past Sunday for a “brief period of time.”

“Our security systems immediately detected the breach, and we took direct action to rectify the situation in order to protect RedTube users,” MindGeek told MalwareBytes.

“RedTube pursues stringent privacy requirements and maintains the highest industry standards of privacy protection to secure not only their assets and properties, but to provide comprehensive protection of their customers’ data when visiting a RedTube-owned site.  

"RedTube is committed to providing their customers with an optimal online experience and the peace of mind when they are accessing a RedTube site.”

According to reports, RedTube is not the only adult tube site to have fallen victim to malware in recent months.

Another site, xHamster, was said to be serving up a Flash file that exploited a flaw via a malicious advertisement.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

My.Club Appoints Nicole Aniston Newest Brand Ambassador

My.Club has named Nicole Aniston its newest brand ambassador.

Elevated X Implements Age Verification Solution, Integration API

Elevated X is now offering age verification services (AVS) through an API.

MojoHost Unveils 'Star Wars Day' Promo

MojoHost will celebrate “Star Wars Day” on Saturday by offering a special discount on new purchases of dedicated servers, VPS, and CDN prepay plans for the whole month of May.

2024 XBIZ Miami Show Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Miami, the adult industry's biggest summer conference, set to take place May 13-16.

Video: FSC's Alison Boden Testifies Before California Assembly Committee Regarding Age Verification

Free Speech Coalition Executive Director Alison Boden testified before the California Assembly Judiciary Committee on Tuesday, in opposition to the state’s version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Princess Mindy Is LoyalFans' 'Featured Creator' for May

LoyalFans has named Princess Mindy as its Featured Creator for May.

Republicans Behind Oklahoma's New Age Verification Law Gleeful About Potential Pornhub 'Exit'

Republican Gov. Kevin Stitt has signed into law Oklahoma’s version of the age verification legislation being sponsored around the country by anti-porn religious conservative activists.

Woodhull Freedom Foundation Debuts 'Fact Checked by Woodhull' Program

The Woodhull Freedom Foundation has launched its new "Fact Checked by Woodhull" program, which uses peer-reviewed research, compiled and analyzed by professional researchers, to debunk myths weaponized to justify the repression of sex, sexuality and gender expression.

Supreme Court Denies Stay of Texas' Age Verification Law

The U.S. Supreme Court has denied a request by Free Speech Coalition (FSC) and other plaintiffs to stay Texas’ controversial age verification law while the court decides on a petition that would effectively overturn it on constitutional grounds.

QueerCrush Relaunches Through YourPaysitePartner

QueerCrush.com has relaunched through YourPaysitePartner (YPP).

Show More