TorrentFreak

The place where breaking news, BitTorrent and copyright collide

RIAA Site Features TorrentFreak’s Latest News

Just a couple of days ago we reported that the MPAA’s website was vulnerable to an XSS attack, which left it displaying torrents from The Pirate Bay. This time a flaw has been discovered in the RIAA’s site, which now allows it to display TorrentFreak’s latest articles.

A cross-site scripting (XSS) attack is a kind of security vulnerability typically found in web applications which allows code to be injected into web pages. The ‘cross site’ element explains how a malicious website could load another site into a frame, giving the appearance that the data all originates from the target site.

Last year we reported that the RIAA’s website had suffered an XSS attack and just a couple of days ago we revealed how the MPAA site was vulnerable to an XSS attack too, one which left it embarrassingly displaying torrents from The Pirate Bay.

Now it is the RIAA’s turn (again) to suffer the same fate. Vektor, who also discovered the MPAA site exploit, told TorrentFreak that he had managed to find a security hole in RIAA.com too. He demonstrated this by using an iframe – an HTML element which makes it possible to embed an HTML document inside another HTML document – TorrentFreak for example.

RIAA.com featuring TorrentFreak

RIAA xss

As with the MPAA site exploit, Vektor explains that his work on the RIAA site is a proof of concept and should be taken as a joke.

We’re sure the RIAA and MPAA coders will be laughing heartily as they try to plug these holes.

Related Posts

Previous Post | Next Post

  • Mediaget
  • Download Torrents with BTguard

NewsBits

The latest news from around the web, not covered on the frontpage

  • RIAA: “Misinformation May Be a Dirty Trick, But It Works.”

    For years the RIAA has tried to convince the world that piracy is killing musicians. Supported...

  • Russia’s Largest BitTorrent Tracker Under Huge DDoS Attack

    RUTracker, Russia’s largest BitTorrent tracker, has been dealing with the effects of a DDoS attack over...

  • Reddit and WordPress Urge Congress to Shelve SOPA/PIPA

    A coalition of 70 groups, including Reddit and WordPress, are asking Congress to stop working on...

  • Turbobit.net Blocks US Visitors After MegaUpload Shutdown

    In the aftermath of the MegaUpload shutdown, file-hosting sites continue to change their services. After Uploaded.to,...

  • QuickSilverScreen Streaming Links Site Calls It Quits

    In the wake of the Megaupload raids and attacks on domains in the US and elsewhere,...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

RecommendedArticles

A selection of some TorrentFreak's classics dug up from our archives.