On the eve of the presidential primary in Pennsylvania, an online prankster leveraged a security vulnerability on Sen. Barack Obama’s campaign Web site to redirect visitors to Sen. Hillary Rodham Clinton’s campaign site. According to Symantec, someone embedded computer code into a posting on the Obama blog. The content in this case targeted a cross-site scripting flaw (XSS), an exceedingly common type of vulnerability that can be used to automatically redirect Web browsers viewing the affected page to another site. The redirect was posted shortly after the Obama site was listed at xssed.com, a collaborative online archive of cross-site scripting vulnerabilities present in thousands of Web sites. While the episode appears to have been little more than a prank, the Web site flaw could have been used for more nefarious purposes, such as silently installing malicious software from third-party sites or popping up a fake campaign contribution page to steal