Public sector IT & e-Government news, job vacancies, public sector tenders from PublicTechnology.net
Advertise on our sites  |  About us  |  Contact us RSS news feeds
Free news email alerts from Publictechnology.net: Sign up here
Feb 09, 2010 - 04:21 PM
Join & login to submit articles
Want to join?  or  Login
Central Government
Ministry of Defence hit by cross site scripting (XSS) flaw


 Tag:  Central Government    Print article: Printer friendly page    Email article: Send this story to a friend       This was published: 14 Aug 2009 - 07:30 am   

The ongoing problem of cross site scripting (XSS) flaws has hit the Ministry of Defence, Fortify Software, the application vulnerability specialist, has reported.

Richard Kirk, Fortify's European Director, says that the MoD admitted to the flaw on Tuesday, after it was alerted to the XSS problem by a journalist who had been tipped off by the hacker group, Team Elite.

"XSS vulnerabilities are often found in Web applications which allow code injection by malicious Internet users into the pages viewed by other users. Examples of these flaws include client-side scripts. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy," he said.

"Research by Symantec in 2007 (http://preview.tinyurl.com/3q9j7w) revealed that around 80 per cent of documented site vulnerabities were down to XSS security problems," he added.

According to Kirk, in many cases of an XSS-driven infection, the infected user is usually unaware his/her computer has been compromised, and is leaking information

This, is he explained, what makes XSS flaws so insidious, as - in common with other similar security problems - the flaw on the MoD Web site could have re-routed users to a second, infected portal.

Kirk went on to say that the XSS flaw only appears to have affected the MoD's A to Z index, but the good news is that the MoD Webmaster appears to have responded almost immediately to the Team Elite warning.

Team Elite's Maciej Bukowski posted details of the MoD site flaw late on Sunday and the MoD was alerted to the problem after Bukowski contacted the ZDnet newswire on Monday.

"Since Bukowski was responsible for revealing a similar flaw on the MI5 Web portal last month, it looks like the message has got through and the MoD reacted swiftly to the Team Elite posting, as soon as ZDNet alerted them to the problem," said Kirk.
Posted by: Editor 



Other latest articles on the subject of Central Government

· Mandelson looks to Germany for lessons in tech innovation   (5 Feb 2010 )
· ICT can make travel greener   (29 Jan 2010 )
· Impact of cuts on technology to be examined   (25 Jan 2010 )
· National ID cards available to London youth   (25 Jan 2010 )
· Gartner: The future is bright but it’s a long haul ahead for public sector CIOs   (19 Jan 2010 )
· e-Borders coverage levels revealed   (19 Jan 2010 )
· Challenges to Effective Collaboration in US Intelligence Community   (18 Jan 2010 )
· HMG breaks its own 10 day payment pledge to SMEs   (18 Jan 2010 )
· Salesforce.com pledges more dollars to Haiti relief agency appeal   (18 Jan 2010 )
· Cameron on energy: the UK is vulnerable   (18 Jan 2010 )

>>>More articles on Central Government>>>

L A T E S T   J O B S

My TechTenders.net Account:

• My Website login
• My Subscription login
• Subscribe to TechTenders.net


My PublicTechnology.net contributer Account:

• PublicTechnology.net Account
• PublicTechnology Emails
About:

• About us
• Contact us
• Terms & conditions of use
• Privacy policy
• RSS feeds: Publictechnology

Copyright:

Copyright Public Technology Ltd 2003-2009. Crown copyright material used under click use licence C02W0007583. Parliamentary material used under click use licence P2005000039, & reproduced with the permission of the Controller of HMSO on behalf of Parliament. EU tender information published under license from the European Commission.

This web site automatically and continually monitors, collects and publishes latest breakings news from a large number of sources. Copyright of content / material may belong to the original source.
Advertise to our audiences:

• Advertising options
• Directory listings
• Advertise Jobs
• Advertise Tenders
• Promote Events
• Sponsor the Awards
• Publish press releases
• Promote products or services
The Public Technology
digital information network:


Public Technology is the UK's foremost news & information provider for the public sector & its suppliers.

It comprises:
• Techtenders.net
• PublicTechnology.net
• Jobs.PublicTechnology.net
• Public Technology email alerts
• PublicPolitics.net
• PublicPages.net
• WhitehallPages.net
• EducationPages.net
• EUmonitor.net
• PublicTenders.net
• NHStenders.net
• e-Government National Awards