4/24/2008

Hack into Obama campaign site exploited a coding flaw

Filed under: Aviran Mordo @ 2:22 am

A simple flaw in the coding of Sen. Barack Obama’s Web site led to a hacking switcheroo of presidential proportions just days before the important Pennsylvania primary.

Some supporters who tried to visit the community blogs section of Obama’s site started noticing late last week they were being redirected to Sen. Hillary Rodham Clinton’s official campaign site.

Security researchers said a hacker exploited a so-called “cross-site scripting” vulnerability in Obama’s Web site to engineer the ruse.

Netcraft Ltd. said the hacker injected code into certain pages in the section - code that was then executed when subsequent visitors tried to view the community blogs section. The vulnerability has since been fixed.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress