Aussie anti-terror site suffers glitch

By Patrick Gray, ZDNet Australia
Monday, December 30, 2002 10:27 AM
Australia's online anti-terrorism campaign has suffered an embarrassing hiccup, with its new national security Web site being vulnerable to low-level cross-site scripting security attacks.

The Web site provides a single access point for national security information from the Australian government and was launched as a part of a comprehensive public information campaign.

It provides information to Australians about potential terrorist threats, travel advice and the latest news on national security issues, such as the current expansion of Australia's counter-terrorism capabilities.

However, the Web site carries its own vulnerabilities which, while not serious, are undesirable.

Users of the website can write HTML strings directly into the page’s search function. When the results page is returned, the HTML code entered into the search function will be displayed. Most sites prevent this occurence by blocking non-alphabet characters such as "<" or "/" from the input field.

The vulnerability makes it possible to embed images and documents from other sites in the page that is returned to the user.

In the most severe instances, cross-site scripting vulnerabilities make it possible for attackers to craft links to vulnerable sites that look legitimate.

These sites could offer both the legitimate content of the target site, and malicious content such as self-installing Trojan horse programs or misleading information.

It is not known if Australia's national security Web site is vulnerable to these extreme cases, but the mere fact that a cross-site scripting vulnerability exists will surely turn a few faces red at its Attorney General’s (AG) office, who maintain the site.

The AG's office was unavailable for comment at the time of writing.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web