CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
April 21st, 2008

Hacked Obama Site Redirects Visitors to Clinton’s Site

A cross-site scripting vulnerability in the social networking section of Sen. Barack Obama’s campaign site was exploited over the weekend to redirect users to the URL of his rival, Sen. Hillary Clinton. Cross-site scripting vulnerabilities, which are most commonly exploited by identity thieves and phishers, let attackers inject their own malicious code into legitimate pages. According to the U.K.-based anti-fraud company Netcraft Ltd., someone identified only as “Mox” confessed to the hack in an entry on the Community Blogs section on the Obama site Sunday. Obama, an Illinois Democrat, leads Clinton in the race for the party’s presidential nomination. The site exploit occurred just before this week’s big Pennsylvania primary.

An Obama supporter captured the cross-site scripting hack and the resulting redirect to Clinton’s campaign site on video Saturday, and posted it on YouTube. Clicking on the “Community Blogs” link, the video showed, sent users to hillaryclinton.com.

Additional vulnerabilities were spelled out by Dimitris Pagkalos, a 22-year-old security researcher who co-manages an online archive of sites vulnerable to cross-site scripting attacks. According to Pagkalos, Obama’s site harbors two still-unpatched bugs. Pagkalos also provided more detail on the redirect that Mox implemented over the weekend, noting that the attack used an IFRAME injected into the title parameter of a personal group, another social networking feature of the Obama site, that then let Mox remotely call some malicious JavaScript.

The bug, said Pagkalos, could have been used to infect Obama’s supporters and site visitors with malware, adware or identity-stealing spyware.

Obama’s campaign did not reply to a request for comment. The cross-site scripting bug has been patched.

Share this item with others:

More on CyberInsecure:
  • Fort William Mountain Bike World Cup 2009 Site Hijacked, Redirects Visitors To Rogue Anti-Virus Page
  • My.BarackObama.com Infects Visitors With Trojan
  • Texas National Guard Website Remains Unavailable After Malware Infection
  • Malaysian Kaspersky Antivirus Website Has Been Hacked In An SQL Injection Attack
  • Spam Promoting Obama’s Video Confessions Installs Trojan

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Hacked Obama Site Redirects Visitors to Clinton’s Site

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.