Hey YouTube... errr. Google! The '
Forgot Username' functionality has an problem. I got a nice little e-mail from your system this morning that reads:
YouTube™ – Broadcast Yourself
The following YouTube username is attached to this email address: . We hope this helps.
Thanks for using YouTube!
— The YouTube Team
To change or cancel your email notifications, go to your email options
Copyright © 2006 YouTube, Inc.
Seems like someone thought my email address was the one they used when they signed up with YouTube. I even got 4 copies of it. They were really convinced this was their e-mail address.
I love a good mystery, so I looked a little deeper. Was this Spam? Was this a phishing attempt? Nope, just a good ol' fashion hole. The kind that most web applications these days cover in day-1 of design requirements.
The functionality YouTube uses to send a reminder e-mail for a forgotten username just sends e-mail to whatever address is entered into the form field. If they have a username for it they just append it to the message.
And if they don't have an username on file, that's where the problem is. They don't suppress the message. They still send it... ugh. And with a fancy little blank area where the username is supposed to be. That is useful. And kinda rude.
1,650,000,000 dollars and it comes with holes. Oh, and if you received an e-mail from YouTube and you are a friend of mine, it was probably because I was testing the system.

YouTube forgot username form widget
technorati: YouTube, Google, exploit, problem
Comments:
Created 82 weeks, 5 days ago