<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebProNews &#187; Web Application</title>
	<atom:link href="http://www.webpronews.com/tag/web-application/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webpronews.com</link>
	<description>Breaking News in Tech, Search, Social, &#38; Business</description>
	<lastBuildDate>Mon, 13 Feb 2012 22:31:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Obama&#8217;s Site Hacked; Change Comes From XSS</title>
		<link>http://www.webpronews.com/obamas-site-hacked-change-comes-from-xss-2008-04</link>
		<comments>http://www.webpronews.com/obamas-site-hacked-change-comes-from-xss-2008-04#comments</comments>
		<pubDate>Mon, 21 Apr 2008 23:49:27 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Barack Obama]]></category>
		<category><![CDATA[Hillary Clinton]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Application]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=45128</guid>
		<description><![CDATA[Cross site scripting exploited within the website for Illinois Senator and Presidential hopeful Barack Obama caused visitors to the blog section to be redirected to rival Hillary Clinton's site.
]]></description>
			<content:encoded><![CDATA[<p>Cross site scripting exploited within the website for Illinois Senator and Presidential hopeful Barack Obama caused visitors to the blog section to be redirected to rival Hillary Clinton&#8217;s site.<br />
<span id="more-45128"></span>
<p>
On Saturday night, things were not all right for Obama&#8217;s site visitors. Those who tried to visit the community section of those pages found themselves at an entirely unwanted destination &#8211; the website to elect Hillary Clinton to the Presidency.</p>
<p>
A <a href=http://youtube.com/watch?v=NKjomr1Afq0>video on YouTube</a> showed the redirection in action. <a href=http://www.linkedin.com/in/zennie>Zennie Abraham</a>, who runs a company called Sports Business Simulations, discovered the problem when trying to reach his blog on the Obama site.</p>
<p>
&#8220;This is serious because it means Senator Clinton could also unethically poach donors from the Obama campaign via online website redirects like this,&#8221; he wrote. &#8220;Terrible and unethical.&#8221;</p>
<p>
Abraham also pointed out the site had been developed by Blue State Digital, a design firm that has created numerous sites for Democratic candidates and like-minded people and businesses. A flaw in Obama&#8217;s site could be present in others designed by the firm.</p>
<p>
Someone identifying themselves as <a href=http://my.barackobama.com/page/community/blog/xss>Mox from Liverpool, IL</a>, claimed to be responsible for the attack on the Obama website. &#8220;All I did was exploit some poorly written HTML code,&#8221; wrote Mox.</p>
<p>
By putting certain characters in the blog&#8217;s name when creating it on Obama&#8217;s site, the characters become part of the URL. Put the right characters in it, and if they aren&#8217;t sanitized by the application creating the blog, a cross-site condition would come into being.</p>
<p>
Mox&#8217;s explanatory post ends abruptly, so it isn&#8217;t known if the individual confessed to doing this in support of the Clinton candidacy or not. However, Mox claims the flaw has been fixed on the site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/obamas-site-hacked-change-comes-from-xss-2008-04/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/9 queries in 0.004 seconds using memcached
Object Caching 194/206 objects using memcached

Served from: webpronews.com @ 2012-02-13 17:50:44 -->
