Creative Coding Catches Presidential Hopeful Off-Guard

April 21, 2008 by JR Raphael | 2 comments

By JR Raphael
Contributing Writer, [GAS]

Cross-site scripting is being blamed for a campaign trail hack.

Someone took advantage of weak security to redirect visitors from barackobama.com’s “Community Blogs” section to rival Hillary Clinton’s home page over the weekend.

A user identifying himself as “Mox” claims credit for the move on a post written just before midnight on Obama’s forum:

“I am the one who ‘hacked’ Obama’s site,” he writes. “All I did was exploit some poorly written HTML code.”

Cross-site scripting (or XSS) vulnerabilities let black hats insert their own codes into exposed pages. Obama’s site allowed users to write blog entries that could contain JavaScript code. That can be used to create a redirect effect like the one used this weekend.

While that specific hack has been undone, a videotape of the modified page has now surfaced on YouTube showing the effect the site suffered.

Cross-scripting site XSSed.com also claims Obama’s site has more vulnerabilities and could easily be attacked again, even leading to spyware infections on visitors’ computers.

Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • MySpace
  • FriendFeed
  • del.icio.us
  • Google Bookmarks
Related Posts:
  1. Problem with [GAS] – Can anyone help?
  2. Upgrade Flash Now: 90 Percent of Windows Hosts Vulnerable
  3. Presidential Candidates and New Ways of Reaching Out
  4. 11 Signs Your Presidential Candidate isn’t a Geek
Cool posts on other blogs:
Did you enjoy this post? If so, subscribe to the geeksaresexy RSS feed.

RSS feed | Trackback URI

2 Comments »

Comment by Mackenzie
2008-04-21 12:54:39

He couldn’t have just reported it instead of being an ass? I found a SQL injection vuln in Hillary’s site in December, but I passed the info on to someone I knew could get it up the chain of command to have it fixed. And yes, it was fixed.

 
Comment by Jesmond Darmanin
2008-04-22 06:46:48

i hope they will be able to fix up the vulnerabilities soon! they do need to invest in some proper vulnerability scanning software!

 
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Trackback responses to this post


| [Geeks are Sexy] Privacy Policy | Legal Disclaimer |