<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Obama site hacked, redirects clicks to Clinton&amp;#039;s site - Comments</title>
 <link>http://www.thestandard.com/news/2008/04/21/obama-site-hacked-redirects-clicks-clintons-site</link>
 <description>Comments for &quot;Obama site hacked, redirects clicks to Clinton&#039;s site&quot;</description>
 <language>en</language>
<item>
 <title>Obama site hacked, redirects clicks to Clinton&#039;s site</title>
 <link>http://www.thestandard.com/news/2008/04/21/obama-site-hacked-redirects-clicks-clintons-site</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;A cross-site scripting vulnerability in the social networking section of &lt;a href=&quot;http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Barack+Obama&quot; rel=&quot;nofollow&quot;&gt;Sen. Barack Obama&lt;/a&gt;&#039;s campaign site was exploited over the weekend to redirect users to the URL of his rival, &lt;a href=&quot;http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Hillary+Clinton&quot; rel=&quot;nofollow&quot;&gt;Sen. Hillary Clinton, (D-N.Y.)&lt;/a&gt;, researchers claimed Monday.&lt;/p&gt;
&lt;p&gt;According to the U.K.-based anti-fraud company &lt;a href=&quot;http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Netcraft+Ltd.&quot; rel=&quot;nofollow&quot;&gt;Netcraft Ltd.&lt;/a&gt;, someone identified only as &quot;Mox&quot; &lt;a href=&quot;http://my.barackobama.com/page/community/post/xss/gGCCkL&quot; rel=&quot;nofollow&quot;&gt;confessed to the hack&lt;/a&gt; in an entry on the Community Blogs section on the Obama site Sunday. Obama, an Illinois Democrat, leads Clinton in the race for the party&#039;s presidential nomination. The site exploit occurred just before this week&#039;s big Pennsylvania primary.&lt;/p&gt;
&lt;p&gt;&quot;You may also be wondering, how did you get Hillary&#039;s site to appear where Obama&#039;s should be?&quot; wrote Mox. &quot;The answer to that is, through the magical world of Cross Site Scripting.&quot;&lt;/p&gt;
&lt;p&gt;Cross-site scripting vulnerabilities, which are most commonly exploited by identity thieves and phishers, let attackers inject their own malicious code into legitimate pages.&lt;/p&gt;
&lt;p&gt;An Obama supporter captured the cross-site scripting hack and the resulting redirect to Clinton&#039;s campaign site &lt;a href=&quot;http://youtube.com/watch?v=NKjomr1Afq0&quot; rel=&quot;nofollow&quot;&gt;on video&lt;/a&gt; Saturday, and posted it on &lt;a href=&quot;http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=YouTube+Inc.&quot; rel=&quot;nofollow&quot;&gt;YouTube&lt;/a&gt;. Clicking on the &quot;Community Blogs&quot; link, the video showed, sent users to hillaryclinton.com.&lt;/p&gt;
&lt;p&gt;The cross-site scripting bug has been patched, Mox said Sunday.&lt;/p&gt;
&lt;p&gt;The Community Blogs section of the Obama site lets supporters create their own blogs, and read other supporters&#039; postings. Users must register on the site to access Community Blogs.&lt;/p&gt;
&lt;p&gt;The Obama site isn&#039;t out of the clear, however. &quot;While Mox states that the original issue has now been fixed, a number of similar vulnerabilities have since been identified and remain unfixed,&quot; said Netcraft&#039;s Paul Mutton in an &lt;a href=&quot;http://news.Netcraft.com/archives/2008/04/21/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html&quot; rel=&quot;nofollow&quot;&gt;alert on the security company&#039;s site&lt;/a&gt; Monday.&lt;/p&gt;
&lt;p&gt;The additional vulnerabilities mentioned by Mutton were &lt;a href=&quot;http://xssed.com/news/65/Barack_Obamas_official_site_hacked/&quot; rel=&quot;nofollow&quot;&gt;spelled out by Dimitris Pagkalos&lt;/a&gt;, a 22-year-old security researcher who co-manages an online archive of sites vulnerable to cross-site scripting attacks. According to Pagkalos, Obama&#039;s site harbors two still-unpatched bugs.&lt;/p&gt;
&lt;p&gt;Pagkalos also provided more detail on the redirect that Mox implemented over the weekend, noting that the attack used an IFRAME injected into the title parameter of a personal group -- another social networking feature of the Obama site -- that then let Mox remotely call some malicious JavaScript.&lt;/p&gt;
&lt;p&gt;The bug, said Pagkalos, could have been used to infect Obama&#039;s supporters and site visitors with malware, adware or identity-stealing spyware.&lt;/p&gt;
&lt;p&gt;Just over a week ago, &lt;a href=&quot;http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Oliver+Friedrichs&quot; rel=&quot;nofollow&quot;&gt;Oliver Friedrichs&lt;/a&gt;, director of emerging technologies at Symantec Corp. and a noted researcher on electoral cybercrime, said the &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9077198&quot; rel=&quot;nofollow&quot;&gt;U.S. presidential candidates&#039; campaigns were clueless&lt;/a&gt; about the threat to their Web sites. &quot;There&#039;s just a general lack of awareness,&quot; said Friedrichs in an interview after a presentation he gave no the subject at the RSA Conference.&lt;/p&gt;
&lt;p&gt;Obama&#039;s campaign did not reply to a request for comment.&lt;/p&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/04/21/obama-site-hacked-redirects-clicks-clintons-site#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/1402">IDGNS</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1531">Internet</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1805">Intrusion</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1428">Security</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1607">Sites</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Mon, 21 Apr 2008 10:42:41 -0700</pubDate>
 <dc:creator>IDG News Service</dc:creator>
 <guid isPermaLink="false">105161 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
