Aust anti-terror Web site suffers glitch

By Patrick Gray
30 December 2002 12:10 PM
Tags: web, campaign, government, gray, patrick, terror, national security, site
The online portion of the federal government's anti-terrorism campaign has suffered an embarrassing hiccup, with the new national security Web site vulnerable to low-level cross-site scripting security attacks.

The Web site "...provides a single access point for national security information from the Australian government" and was launched as a part of a comprehensive public information campaign. It provides information to Australians about potential terrorist threats, travel advice and the latest news on national security issues, such as the current expansion of Australia's counter-terrorism capabilities.

However, the Web site carries its own vulnerabilities which, while not serious, are undesirable.

Users of the website can write HTML strings directly into the page's "search" function. When the user clicks on "search" and the results page comes back, the HTML entered into the search function will be displayed. This is prevented from happening on most sites by blocking key non-alphabet characters (such as "<" or "/") from the input field.

The vulnerability makes it possible to embed images and documents from other sites in the page that is returned to the user.

In the most severe cases, cross-site scripting vulnerabilities make it possible for attackers to craft links to vulnerable sites that look legitimate, but offer both the legitimate content of the target site, such as nationalsecurity.gov.au images and HTML, and malicious content that looks like it came from the legitimate site, such as self-installing Trojan horse programs or misleading information.

It is not known if the national security website is vulnerable to any of these worst case conditions, but the mere fact that a cross site scripting vulnerability exists will surely turn a few faces red at the Attorney General's (AG) office, who maintain the site.

The AG's office was unavailable for comment at the time of writing.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Carelessness busts Linux security
    No operating system can ever properly protect a computer from trojans as long as users continue to do silly things. Just because Linux is immune to your standard drive-by viruses it does not mean that it can escape trojan horses.
  • Array Sun shining on Ajnaware
    Graham Dawson talks about the future of iPhone app development and augmented reality.
  • Array Holiday IT to-do lists
    The fast-approaching holiday season is a great time to update your IT systems while everything's quiet.
  • More blogs »

Tags

Back to top

Featured