Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 24th, 2012, 08:19 GMT · By Eduard Kovacs

TeamHav0k’s OP XSS: Vulnerabilities in US Government Sites (Exclusive)

SHARE:

Adjust text size:


TeamHav0k finds XSS vulnerabilities in gov and edu sites
Enlarge picture
After yesterday they revealed that many high-profile websites contained major cross-site scripting (XSS) vulnerabilities, hackers from TeamHav0k stepped it up a notch and initiated OP XSS 2.0 to show that even websites hosted on government (.gov) and education (.edu) domains are highly vulnerable.

In OP XSS 2.0, the hackers focused on websites belonging to the US government and education institutions, but this time their findings come with a message

Aurora University website contains XSS flaws
Enlarge picture
University websites such as the ones belonging to the Rochester Institute of Technology, Arizona State University, NYU Poly’s Center for Advanced Technology in Telecommunications, Michigan State University, Aurora University, DeVry University, University of Hawaii, University of Virginia and Carnegie Mellon University were all proved to be severely flawed from a security standpoint.

While this list may be impressive, the list of government websites is even more so. XSS vulnerabilities were found in Readiness and Emergency Management for Schools, Rhode Island Office of the Secretary of State, Library of Congress, Brookhaven National Laboratory, Virginia Employment Commission, hosted on a Commonwealth of Virginia subdomain, The Nation’s Report Card, and even Feds Hire Vets.

Feds Hire Vets contains XSS vulnerabilities
Enlarge picture
We have managed to contact one of the team’s leaders, Echelon, to find out more details on this latest operation. If after the first operation it seemed like they were a group of gray hats that wanted to show website administrators their assets were not properly secured, it turns out that they’re ready to step to the dark side at any time.

“One thing I will say for sure. If SOPA or PIPA ever resurface 359 companies and corporations will pay for their betrayal to freedom,” he said.

The government website were proven vulnerable to show that the hacker collective means business “and to show that security on a Government server is just pathetic.”

“The edu`s were just for the lulz though I reported them,” he added.

Besides the .edu and .gov websites, the popular comedy site of Turner Broadcasting Systems (TBS) and a free hosting site were also proven to be vulnerable. We have contacted the former to find out whether they plan on taking any measures to resolve the vulnerability.

XSS vulnerabilities are highly common in public websites. Unfortunately, they’re also highly serious because they could allow an attacker to execute arbitrary code and launch malicious campaigns targeting the sites' visitors.

TELL US WHAT YOU THINK:

2,315 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


T-Mobile Hacked by TeaMp0isoN, Administrators and Staff Exposed (Exclusive, Updated)

Hackers Prove EA, IGN, ImageShack, NY Times, Verizon Vulnerable

XSS Attacks Possible due to IE URI Encoding Flaw

Softpedia Introduces: Hackers Around the World

ArcelorMittal Hacked by Anonymous, Tons of Information Leaked

READER COMMENTS:


Comment #1 by: dohn on 31 Jan 2012, 06:24 UTC reply to this comment

If you post a newly found XSS to a disclosure mailing list... it's pretty much ignored.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM