New Zealand Herald falls victim to XSS prank
LATEST NEWS
SUBSCRIBE
Computerworld is New Zealand's only specialised information systems fortnightly. Subscribe now for $100 (23 issues) and save more than 37% off the cover price!
SIGN UP
The New Zealand Herald's website had spinning photos and backward text this morning after it evidently was the victim of an amusing cross-site scripting attack
By Jeremy Kirk | Sydney | Friday, 16 November, 2012 | 5 Comments
The New Zealand Herald's website had spinning photos and backward text on Friday morning after it evidently was the victim of an amusing cross-site scripting attack.
Cross-site scripting is an attack in which a script drawn from another website is allowed to run that shouldn't. In the case of the newspaper, the attack appeared to pull a piece of Javascript from the website of a Los Angeles-based software developer, David Lynch.
Lynch describes himself on his LinkedIn profile as working for deviantART, a social network for artists. He couldn't immediately be reached for comment, but it appears the batch of code, named "eyewonder.js," wasn't specifically intended to target the newspaper website, but rather is a general script designed to manipulate elements on a Web page.
Cross-site scripting, abbreviated as XSS, is one of the most common coding flaws in Web pages but can also have much more dangerous impacts than what visibly affected the New Zealand Herald. An XSS vulnerability can be used to steal data from a website or cause other malicious code to run.
The newspaper, which is owned by APN Holdings NZ Limited, could not immediately be reached for comment.
It may be coincidental, but a hacking conference called Kiwicon is due to kick off tomorrow in Wellington. Kiwicon's blog mentioned the New Zealand Herald's hack this morning, along with two other security-related incidents: a wi-fi outage on an airport bus and payment system problems in Wellington.
It's not unheard of for hackers to show off their skills during conferences by attacking infrastructure or even the computers of other conference attendees. Kiwicon runs until Sunday.
Comments
Nothing to see
That would almost have made the Herald website worth looking at.
Posted by Anonymous at 16:55:25 on November 16, 2012
Posted by Anonymous at 16:55:25 on November 16, 2012
Nothing to see
I totally agree. NZ Herald have gone downhill over the past few years. Useless editing, biased reporters,...
Posted by Anonymous at 9:18:48 on November 19, 2012
Posted by Anonymous at 9:18:48 on November 19, 2012
Nothing to see
We all said, commenting on a COMPUTERWORLD article.
*runs away in shame*
Posted by Satan at 9:02:15 on November 17, 2012
*runs away in shame*
Posted by Satan at 9:02:15 on November 17, 2012
MOST POPULAR
Social Media @Computerworld NZ

Computerworld NZ has now reached LinkedIn! Join to expand your networks and meet others interested in information systems.





