Feeds

Holes in London Mayor websites leave them open to 'e-gaffes'

New levels of XSS for Boris'n'Ken

5 things you didn’t know about cloud backup

Ethical hackers have discovered potentially serious vulnerabilities on the websites of the two principal candidates in today's London Mayoral election.

Both Boris Johnson’s and Ken Livingstone's campaign websites suffer from ‘cross-scripting’ (XSS) vulnerabilities that make it possible for hackers to redirect users to their opponents' websites, or any other site on the web, penetration testing firm SecureTest warns.

An unexpected endorsement

For example, it is simple to have a picture of Boris appear on Ken’s web site or vice versa, as can be seen by following from this Ken shot on Boris’s site link here. The cross-site scripting vulnerabilities on Boris and Ken’s sites are exploited using a simple redirect. In the case of Boris’s site, this is in the search function.

Ken Munro, managing director of SecureTest, explained that the picture prank does not involve hacking either site as such. "It just involves sending somebody a link that pulls content off a third-party site as if it came from the first site, which shouldn't be allowed to happen," he told El Reg.

SecureTest's team of ethical penetration testers found these weaknesses after reading reports of similar vulnerabilities on Hillary Clinton and Barrack Obama’s websites in the US.

Munro said: "This is a classic internet prank that could have very damaging consequences. It is entertaining to direct potential Ken voters to Boris’s website or vice versa. What would happen, however, if some prankster redirected traffic to a pornographic website, or one which downloaded damaging spyware onto a user's computer?

Depending on their nature, cross-site scripting vulnerabilities create a means for hackers to insert a script redirecting users to another website entirely, or an 'iframe' that forces the site to display the content of a third party site. Customers of an Italian online bank were recently attacked in a very similar manner - however, that attack redirected their usernames and passwords to a hacker. ®

The essential guide to IT transformation

More from The Register

next story
One HUNDRED FAMOUS LADIES exposed NUDE online
Celebrity women victimised as Apple iCloud accounts reportedly popped
Rubbish WPS config sees WiFi router keys popped in seconds
Another day, another way in to your home router
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NZ Justice Minister scalped as hacker leaks emails
Grab your popcorn: Subterfuge and slur disrupts election run up
HP: NORKS' cyber spying efforts actually a credible cyberthreat
'Sophisticated' spies, DIY tech and a TROLL ARMY – report
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?