2010-05-01
Abstract
XSS vulnerability in site of project aimed at plugging cyber security skills gap.
Copyright © 2010 Virus Bulletin
A new initiative designed to identify and nurture the UK’s next generation of cyber security experts has encountered a rather embarrassing stumbling block just days after its launch. Cyber Security Challenge UK – which is sponsored by the UK Government’s Office of Cyber Security, SANS Institute, the Institute of Information Security Professionals, QinetiQ Consulting and Dtex Systems – is a series of challenges aimed at testing the nation’s cyber skills and inspiring youngsters to develop their talents in the security arena. Immediately following its launch at the InfoSecurity Europe exhibition, however, the online home of the initiative (http://cybersecuritychallenge.org.uk/) was found to be suffering from an XSS vulnerability. According to Internet security company Netcraft it was possible to inject JavaScript into the site’s title and h2 elements by appending the injected code to the site’s URL. The security hole was quickly fixed, and online candidate registration will open later in the year.