Gen. partnerAlgotech

Free videos from DVTV and Oktagon? Marek Tóth on (and beyond) the bugs in Tivio Studio

Security researcher and ethical hacker Marek Tóth published a detailed analysis of a series of vulnerabilities in the Tivio Studio platform. Due to a misconfiguration and other security issues, his findings show it was possible to gain access to paid content from various creators — including videos from projects such as DVTV, Oktagon, U Kulatého stolu or Čestmír Strakatý.

|
March 12, 2026

Security researcher and ethical hacker Marek Tóth published a detailed analysis of a series of vulnerabilities in the Tivio Studio platform. Due to a misconfiguration and other security issues, his findings show it was possible to gain access to paid content from various creators — including videos from projects such as DVTV, Oktagon, U Kulatého stolu or Čestmír Strakatý.

In the new episode of the CZECH CYBER TV podcast, Marek explains how he discovered these bugs, how they worked and what real impact they could have had. In some cases it was possible to download not only paid content but even videos that had not yet been publicly released.

The interview also includes a discussion of his other security research, specifically the method DOM-based Extension Clickjacking, which could have affected some password managers or browser extensions.

In the episode we also cover:

  • how the responsible disclosure process works
  • how companies respond to security reports
  • how researchers today look for bugs in web applications
  • and Marek's experiences from the DEF CON in Las Vegas

Glossary of terms

A number of technical terms from the fields of cybersecurity and web applications appear in Marek's analysis and our podcast. Below you will find their brief and easy-to-understand explanations.

XSS (Cross-Site Scripting)

One of the most common web vulnerabilities. An attacker can inject their own JavaScript code into a page, which then runs in the victim's browser. This can lead, for example, to data theft, displaying fake content, or taking over a user's logged-in session.

Reflected XSS

A type of XSS vulnerability where the malicious code is part of a link. After clicking, the code is "reflected" through the web application and executed in the victim's browser. Such attacks often spread via social networks, ads, or phishing messages.

Open Redirect

A flaw where a website allows redirecting a user to another address than intended. On its own it may not be critical, but it is often used as part of a larger attack because a trusted domain then redirects the user elsewhere.

URL spoofing

A technique where an attacker alters or masks an address to make it appear more trustworthy than it actually is. A user may see a legitimately-looking URL even though something different is happening in the background.

DOM (Document Object Model)

The structure of a web page that the browser works with. JavaScript can modify a page's content via the DOM — for example text, forms, or buttons. That is why the DOM is important for XSS or clickjacking attacks.

Clickjacking

A type of attack where a user is tricked into clicking something other than what they think. The screen may show an innocuous element, but the user actually clicks a hidden element that performs a different action.

DOM-based Extension Clickjacking

A more advanced technique where an attacker manipulates the page so that the user unknowingly interacts with browser extension elements — for example a password manager.

Session

A user session that tells the server the user is logged in. Thanks to the session, it is not necessary to enter a password for every action.

Session Hijacking

A situation where an attacker gains access to a user session. If they obtain a session token or other authentication credential, they can impersonate the victim without knowing their password.

Token

A digital identifier used to authenticate a user's access to a particular service or resource.

Access token

A short-lived token used to authenticate access to an application or API.

Refresh token

A token used to obtain a new access token without requiring the user to log in again.

IndexedDB

A data storage available directly in the browser. Web applications can store larger amounts of data there. If sensitive information is stored in it and the application contains an XSS vulnerability, an attacker can gain access to it.

localStorage

A simple data storage in the browser. Websites often store settings or identifiers in it. Sensitive data stored in localStorage can be problematic because it is accessible to JavaScript running on the page.

sessionStorage

Similar storage to localStorage, but only for the duration of a specific session or open tab.

Cookies

Small data files that a website stores in the browser. They are used, for example, to maintain a login. If properly configured (for example with the HttpOnly or Secure attributes), they can be safer than normal client-side storage.

Content-Security-Policy (CSP)

A website security mechanism that tells the browser where it may load scripts, styles, or other content from. A correctly configured CSP can significantly limit the impact of XSS attacks.

Firebase

Google's cloud platform that developers use, for example, for authentication, databases, or file storage.

Firebase Storage

A service for storing files in the cloud. If access rules are misconfigured, files can be accessible to the public.

Firebase Firestore

Google's cloud database used for storing application data.

Security Rules

Rules that determine who may read or write data in Firebase.

Broken Access Control

A flaw in access control. The application fails to properly verify who has permission to certain content.

IDOR (Insecure Direct Object Reference)

A type of access control bug. An attacker changes an identifier in a URL or API request and gains access to another object, for example another video or document.

MPD file

A file used for streamed video (MPEG-DASH). It contains information about where the player should fetch the individual parts of the video from.

BaseURL

A part of the MPD file specifying the base address from which video segments should be loaded.

MPEG-DASH

A standard for streaming video in chunks. Video is played progressively from smaller segments.

Video segments

Small parts into which streamed video is divided.

RSS feed

A data format used, for example, for podcasts or automatic fetching of new content.

DevTools

Developer tools in the browser that allow analyzing a web page's behavior.

Network panel

The part of DevTools that shows communication between the browser and the server.

Metadata

Supplementary information stored in files — for example information about the author, used software, or technical parameters.

Responsible disclosure

The process of responsibly reporting a security flaw. The researcher first informs the company and gives it time to fix the issue before it is made public.

90-day disclosure

An approach used by some security researchers where the company is given roughly 90 days to fix a vulnerability before it is disclosed.

Bug bounty

A program in which companies reward security researchers for discovered vulnerabilities.

security.txt

A standardized file on an organization's website that contains contact information for reporting security vulnerabilities.

Pentest

Short for penetration test — controlled security testing of a system intended to uncover weaknesses before attackers do.

Social engineering

Manipulating people in order to obtain information or access to a system.

Phishing

A type of fraud where an attacker tries to trick users into revealing sensitive data, such as passwords or payment information.

Trusted domain

A web address of a well-known service or brand. That's why vulnerabilities on trusted domains are especially dangerous — users often automatically trust them.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.