Spook Links - The Ultimate Black Hat Link Building Technique
Here’s a rippingly funny find from John Leach’s Blog uncovering an XSS vulnerability on the CIA’s very own Freedom of Information web site:
The CIA Freedom of Information website had the dumbest security hole in it. With all the recent hoo har about the “Family Jewels” documents, you’d expect they’d do a quick once over on this stuff. All the textual content on the document view pages is generated directly from variables passed in the url - with no input validation.
This opens them up to cross site scripting attacks (XSS) and really is just stupid. Lucky they aren’t the GUARDIANS OF THE LARGEST CACHE OF SENSITIVE INFORMATION IN THE WORLD or anything - *phew*.
John has built a web site of his own with a generator which allows you to publish your own stuff on the CIA FOIA site: http://geekz.co.uk/cia-foia/
We’ve preserved a few screenshots in case it gets pulled soon which is only too likely:

Here’s the generator proper:

And to prove it all, here’s an example page generated and displayed from the CIA site:

Now before anyone goes about merrily spamming the spooks, you may want to considers John’s dark premonition:
I guess that from tomorrow, any mail for me should be addressed to Guantanamo Bay.
Maybe he’s right in pointing out that it would (subjunctive case!) actually be you who’s liable for the exploit, but then he’s no lawyer AFAIK, and as they say in law as much as in SEO: a little knowledge is a dangerous thing.
So, watch it, beagle: You’ll be doing so at your own risk!
[ ]
Trackback link: http://fantomaster.com/fantomNews/archives/2007/06/28/spook-links-the-ultimate-black-hat-link-building-technique/trackback/
![[Home]](http://fantomaster.com/images/shim.gif)






















