NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

Incidents


MI5 and WHO Websites Compromised

Vulnerable to cross-site scripting attacks

By Lucian Constantin, Web News Editor

22nd of July 2009, 11:33 GMT

Adjust text size:


MI5 and World Health Organization websites vulnerable to XSS attacks
Enlarge picture
Websites belonging to UK's national security agency, the MI5 (Millitary Intelligence, Section 5) and the World Health Organization (WHO) have been found vulnerable to cross-site scripting attacks. The weaknesses allow attackers to inject rogue IFrames, prompt JavaScript alerts or redirect visitors to other potentially malicious Web pages.

The cross-site scripting flaws were reported by a member of a group of programmers and security enthusiasts calling themselves Team Elite. Going by the online handle of [-TE-]-Neo, the grey hat hacker posted screenshots of several proof-of-concept XSS attacks against the two websites.

Cross-site scripting, or XSS, is a type of vulnerability that facilitates injecting rogue code into otherwise legit Web pages. Such flaws generally result from failure to properly validate user input into forms and can have different levels of impact, with persistent or Type 2 XSS being the most severe.

It is worth noting that, in the case of the MI5 and WHO websites, the cross-site weaknesses are non-persistent, or Type 1, and can only be exploited by opening malformed URLs. However, this does not mean that they are not dangerous.

Non-persistent XSS vulnerabilities can be used to significantly increase the credibility of phishing or malware-distribution campaigns. Instead of having to trick a user into visiting a fake page hosted on a dubious domain, the attacker can link to a vulnerable page on the legit domain directly.

The weakness in the MI5 website is located in the search form, which allows passing code as a search string. This can be used to inject a rogue IFrame into the page, which can, in turn, load more malicious code from a third-party domain via its src= attribute.

The WHO website has a very similar problem, with the search form being exploitable in the same manner. For a funny demonstration, Neo has injected an image of a flying pig into its search result page, to suggest how the World Health Organization is currently coordinating the global fight against swine flu.

According to the hacker, the administrators of both websites have been notified, but, at the time of writing this article, the MI5 site was still vulnerable.

Rogue JavaScript prompt on MI5 website
Enlarge picture
IFrame injection on MI5 website
Enlarge picture
Rogue JavaScript prompt on WHO website
Enlarge picture
IFrame injection on WHO website
Enlarge picture


TAGS:

MI5 | World Health Organization | cross-site scripting | XSS attack | IFrame injection
Read by 3,837 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


New Mozilla Technology to Mitigate Cross-Site Scripting

MSN Canada Website Compromised by Hackers

Multiple Visa Websites XSSed

U.S. Bank and Bank of America Websites Vulnerable

The Website of the International Federation of the Phonographic Industry XSSed

Adobe Vulnerable to XSS Because of Buggy Flash Files

PayPal Registration Page XSSed

Universal Google Cross-Site Scripting Flaw Discovered

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM