{"id":3451,"date":"2008-04-22T02:42:51","date_gmt":"2008-04-22T00:42:51","guid":{"rendered":"http:\/\/www.pasteris.it\/blog\/2008\/04\/22\/da-barack-obama-ad-hillary-clinton-attraverso-un-hacker\/"},"modified":"2008-04-22T02:42:51","modified_gmt":"2008-04-22T00:42:51","slug":"da-barack-obama-ad-hillary-clinton-attraverso-un-hacker","status":"publish","type":"post","link":"https:\/\/www.pasteris.it\/blog\/2008\/04\/22\/da-barack-obama-ad-hillary-clinton-attraverso-un-hacker\/","title":{"rendered":"Da Barack Obama ad Hillary Clinton attraverso un hacker"},"content":{"rendered":"<p><a href=\"http:\/\/news.netcraft.com\/archives\/2008\/04\/21\/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html\"> via Netcraft<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/news.netcraft.com\/archives\/2008\/04\/21\/hillary.png\" alt=\"hillary.png\" align=\"right\" border=\"0\" height=\"187\" width=\"330\" \/><\/p>\n<blockquote><p>  A security weakness in <a href=\"http:\/\/www.barackobama.com\/\">Barack Obama&#8217;s<\/a> website has been exploited to redirect visitors to <a href=\"http:\/\/hillaryclinton.com\/\">Hillary Clinton&#8217;s<\/a> website. Visitors who viewed the <a href=\"http:\/\/my.barackobama.com\/page\/community\/members\">Community Blogs<\/a> section of the site were instead presented with Clinton&#8217;s website as a result of a cross-site scripting vulnerability.<\/p>\n<p>A user named Mox, from Liverpool, IL, posted an <a href=\"http:\/\/my.barackobama.com\/page\/community\/post\/xss\/gGCCkL\">apparent confession<\/a> in the Community Blogs section on the Barack Obama website yesterday. The subject of the post was, &#8220;<em>I am the one who &#8220;hacked&#8221; Obamas site.<\/em>&#8221;<\/p>\n<p>Mox plays down the matter by saying that all he did was exploit some poorly written HTML code before suggesting that it was a cross-site scripting vulnerability that had been exploited. By allowing users to enter characters such as &gt; and &#8221; into their blog URLs, JavaScript could be injected into pages in the Community Blogs section and would be executed by subsequent visitors.<\/p>\n<p>A YouTube clip from zennie62 <a href=\"http:\/\/youtube.com\/watch?v=NKjomr1Afq0\">demonstrates the attack<\/a>. The clip shows a user clicking on the Community Blogs section of the Barack Obama site, which subsequently causes the browser to redirect to <a href=\"http:\/\/hillaryclinton.com\/\">hillaryclinton.com<\/a>. The author speculates that &#8220;<em>Senator Clinton&#8217;s staffers possibly hired someone to hack into the Barack Obama website system<\/em>.&#8221; No evidence is offered to back up this statement.<\/p><\/blockquote>\n<p><video>http:\/\/youtube.com\/watch?v=NKjomr1Afq0<\/video><\/p>\n","protected":false},"excerpt":{"rendered":"<p>via Netcraft A security weakness in Barack Obama&#8217;s website has been exploited to redirect visitors to Hillary Clinton&#8217;s website. Visitors who viewed the Community Blogs section of the site were instead presented with Clinton&#8217;s website as a result of a cross-site scripting vulnerability. A user named Mox, from Liverpool, IL, posted an apparent confession in &#8230; <a title=\"Da Barack Obama ad Hillary Clinton attraverso un hacker\" class=\"read-more\" href=\"https:\/\/www.pasteris.it\/blog\/2008\/04\/22\/da-barack-obama-ad-hillary-clinton-attraverso-un-hacker\/\" aria-label=\"Per saperne di pi\u00f9 su Da Barack Obama ad Hillary Clinton attraverso un hacker\">Leggi tutto<\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[2157,87,168,248,354,363,376],"class_list":["post-3451","post","type-post","status-publish","format-standard","hentry","tag-blog","tag-browser","tag-hacker","tag-obama","tag-video","tag-web","tag-youtube"],"_links":{"self":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts\/3451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/comments?post=3451"}],"version-history":[{"count":0,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/posts\/3451\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/media?parent=3451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/categories?post=3451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pasteris.it\/blog\/wp-json\/wp\/v2\/tags?post=3451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}