PDA

View Full Version : Security Flaw in CNN.com?



Huffers
April 22nd, 2006, 10:50 PM
I've noticed that videos on CNN.com, eg the one linked to on this page
http://www.cnn.com/2006/US/04/21/nail.gun.ap/index.html
check that Windows Media Player is installed before allowing you to play them.

Assuming it's their intention to exclude non-microsoft solutions (eg totem, mplayer) I'm pretty sure their mechanism for checking the brand of the player is vulnerable to spoofing by unscrupulous hackers.

Also, their site doesn't even check the brand of web browser before sending the html data -- thus allowing people using non-microsoft solutions such as Opera and Firefox access to the site!

I'm wondering about sending them an email warning about these site vulnerabilities, what do people think?

d351GuJu
April 22nd, 2006, 11:00 PM
Weird, you just posted this and none of the videos are available anymore @ CNN. Here's what I get:

"The page you requested cannot be found. The page you are looking for might have been removed, had its name changed, or is temporarily unavailable."

enopepsoo
April 23rd, 2006, 12:57 AM
CNN is to news what Microsoft is to software.