CyberInsecure.com

Daily cyber threats and internet security news alerts
April 21st, 2008

Hacked Obama Site Redirects Visitors to Clinton’s Site

A cross-site scripting vulnerability in the social networking section of Sen. Barack Obama’s campaign site was exploited over the weekend to redirect users to the URL of his rival, Sen. Hillary Clinton. Cross-site scripting vulnerabilities, which are most commonly exploited by identity thieves and phishers, let attackers inject their own malicious code into legitimate pages. According to the U.K.-based anti-fraud company Netcraft Ltd., someone identified only as “Mox” confessed to the hack in an entry on the Community Blogs section on the Obama site Sunday. Obama, an Illinois Democrat, leads Clinton in the race for the party’s presidential nomination. The site exploit occurred just before this week’s big Pennsylvania primary.

An Obama supporter captured the cross-site scripting hack and the resulting redirect to Clinton’s campaign site on video Saturday, and posted it on YouTube. Clicking on the “Community Blogs” link, the video showed, sent users to hillaryclinton.com.

Additional vulnerabilities were spelled out by Dimitris Pagkalos, a 22-year-old security researcher who co-manages an online archive of sites vulnerable to cross-site scripting attacks. According to Pagkalos, Obama’s site harbors two still-unpatched bugs. Pagkalos also provided more detail on the redirect that Mox implemented over the weekend, noting that the attack used an IFRAME injected into the title parameter of a personal group, another social networking feature of the Obama site, that then let Mox remotely call some malicious JavaScript.

The bug, said Pagkalos, could have been used to infect Obama’s supporters and site visitors with malware, adware or identity-stealing spyware.

Obama’s campaign did not reply to a request for comment. The cross-site scripting bug has been patched.

Email, Bookmark or Share:
  • E-mail this story to a friend!
  • Digg
  • del.icio.us
  • StumbleUpon
  • Reddit
  • Technorati
  • Slashdot
  • Propeller
  • Google
  • Live
  • YahooMyWeb
  • Facebook
  • LinkedIn
More on CyberInsecure:
  • Texas National Guard Website Remains Unavailable After Malware Infection
  • Malaysian Kaspersky Antivirus Website Has Been Hacked In An SQL Injection Attack
  • Phoenix Mars Lander Website Defaced By Script Kiddies
  • Thousands Of Sites Infected In Renewed SQL Injection Attacks
  • Sony USA PlayStation Website SQL Injected And Redirects Visitors To Fake Anti-Virus Scam

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Hacked Obama Site Redirects Visitors to Clinton’s Site

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. Please leave your real email, it wont be published.

    *
    To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
    Click to hear an audio file of the anti-spam word