On CHOW: Sexy vampire party
BNET Business Network:
BNET
TechRepublic
ZDNet

April 21st, 2008

Obama site hacked; Redirected to Hillary Clinton

Posted by Larry Dignan @ 12:35 pm

Categories: Exploit code, Hackers, Vulnerability research

Tags: Blog, Hillary Clinton, Site, Blogging, Hacking, Security, Internet, Larry Dignan

With a day to go before a critical Pennsylvania Democratic primary, Barack Obama’s team has been busy patching security holes.

According to Netcraft, a hacker exploited security flaws in Obama’s site to redirect traffic to Hillary Clinton’s site. Anyone that visited Obama’s community blogs section of the site was sent to Clinton.

Someone named Mox confessed to the hack in an Obama community blog:

First, let me explain why I put hacked in quotation marks. It is because e what I did was not hacking in the sense that I burrowed into some dusty served and changed the Obama site and stole all your credit card numbers. All I did was exploit some poorly written HTML code.

So, you may be wondering, I never saw this hacking! Well, apparently someone videotaped it. http://youtube.com/watch?v=NKjomr1Afq0. You may also be wondering, how did you get Hillary’s site to appear where Obama’s should be. The answer to that is, through the magical world of Cross Site Scripting. http://en.wikipedia.org/wiki/Cross-site_scripting.

You might be wondering, how did you get xss to work here? First, go to your manage blog tab. Then go to Edit Settings. You see how you can put anything you want as a blog URL? Well, its fixed now, but before you could put in any characters you wanted. Including >, “, and

Here’s the YouTube demonstration via YouTube. Also see XSSed and Computerworld.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 44 Talkback(s)
RE: Obama site hacked; Redirected to Hillary Clinton
I feel the hacking of a website has nothing to do with his ability to lead the nation.They deface and hack sites all the time.I been on the net for 10yrs and it always happens and not going to stop.Give it a break.Get over being mad because he didnt choose Mrs.Clinton as a running mate.... (Read the rest)
Posted by: tgardley Posted on: 08/25/08 You are currently: a Guest | | Terms of Use
You'd be amazed how many sites are out there  fr0thy2 | 04/21/08
I was suprised...  storm14k | 04/21/08
I just looked at a few sites  fr0thy2 | 04/21/08
ahem  Jack-Booted EULA | 04/21/08
RE: Obama site hacked; Redirected to Hillary Clinton  fr0thy2 | 04/21/08
Juvenile  John L. Ries | 04/21/08
Obscurity != Security  fr0thy2 | 04/21/08
Didn't say it was  John L. Ries | 04/21/08
Security  dontnetcoder | 04/21/08
psst dontnetcoder, your ignorance is showing  james.faction | 04/21/08
Security Error Magnfied  dontnetcoder | 04/21/08
I believe it is your bias that is showing, not mine.  james.faction | 04/21/08
Concern  dontnetcoder | 04/21/08
"concerns about his ability to lead a nation" - yep, that's bias.  james.faction | 04/21/08
Well Put  dontnetcoder | 04/21/08
More Holes in that Argument than a Pound of Swiss  ESoyke | 04/22/08
After reading two of your posts...  jasonp@... | 04/22/08
Bad Read  dontnetcoder | 04/22/08
book smarts != common sense  JT82 | 04/22/08
Hmmm... a little shy on common sense I see.  i8thecat | 04/23/08
Crossing the street  dontnetcoder | 04/21/08
So he hired a duff web company.  odubtaig | 04/21/08
Valid  dontnetcoder | 04/21/08
Question  dontnetcoder | 04/21/08
ok to call the current president a moron?  james.faction | 04/21/08
Not sure you read that right.  odubtaig | 04/22/08
It's not okay to call Bush a moron...  Roc Riz | 04/22/08
I thought the same thing  John Zern | 04/21/08
Never said that.  odubtaig | 04/22/08
Coding contest.  viztor | 04/22/08
Did ya ever once stop to think???  i8thecat | 04/23/08
CIA to the Rescue!  Giorgio Maone | 04/21/08
You're an idiot, and to show why...  zkiwi | 04/22/08
RE: Obama site hacked; Redirected to Hillary Clinton  JABBER_WOLF | 04/21/08
obama follows murphy's law of inferiority!  xspecx | 04/22/08
...and if a tree falls in the woods...  odubtaig | 04/22/08
Murphy or Peter?  boomchuck1 | 05/01/08
Message has been deleted.  zaine_ridling | 04/22/08
RE: Obama site hacked; Redirected to Hillary Clinton  gswenson | 04/22/08
An illogical reach  Chi Stan | 04/24/08
Doubt it was "hacked"  wackoae | 05/11/08
Obama - Hillary 08' already!  savagesteve13 | 05/20/08
Obambi vs. Clintzilla?  fjcaherfr | 06/02/08
RE: Obama site hacked; Redirected to Hillary Clinton  tgardley | 08/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc