Interesting People mailing list archives

AP: Hack into Obama campaign site exploited a coding flaw


From: David Farber <dave () farber net>
Date: Thu, 24 Apr 2008 07:51:58 -0700


________________________________________
From: Joseph Lorenzo Hall [joehall () gmail com]
Sent: Thursday, April 24, 2008 10:46 AM
To: David Farber
Subject: Clinton Hackers? AP: Hack into Obama campaign site exploited a coding flaw

http://www.washingtonpost.com/wp-dyn/content/article/2008/04/23/AR2008042302976.html

By JORDAN ROBERTSON
The Associated Press
Wednesday, April 23, 2008; 6:53 PM

SAN JOSE, Calif. -- A simple flaw in the coding of Sen. Barack Obama's
Web site led to a hacking switcheroo of presidential proportions just
days before the important Pennsylvania primary.

Some supporters who tried to visit the community blogs section of
Obama's site started noticing late last week they were being
redirected to Sen. Hillary Rodham Clinton's official campaign site.

Security researchers said a hacker exploited a so-called "cross-site
scripting" vulnerability in Obama's Web site to engineer the ruse.

Netcraft Ltd. said the hacker injected code into certain pages in the
section _ code that was then executed when subsequent visitors tried
to view the community blogs section. The vulnerability has since been
fixed.

...

--
Joseph Lorenzo Hall
UC Berkeley School of Information
http://josephhall.org/

-------------------------------------------
Archives: http://www.listbox.com/member/archive/247/=now
RSS Feed: http://www.listbox.com/member/archive/rss/247/
Powered by Listbox: http://www.listbox.com


Current thread: