Skip to Content

Apple's iTunes Affiliates site briefly subjected to image swaps

Our friends over at OS X Daily passed along their story noting that Apple's site for iTunes Affiliates was vulnerable to a cross-site URL trick, letting you substitute your own images for the ones normally displayed on the page. Since the site is intended to let websites display a custom top banner, this was 'as designed' -- at least until jokesters began taking advantage.

The trick works (or at least, it did) by taking the default URL from the web browser and replacing a few things like the artist name, album name, album thumbnail source and the image link.

The Internet moves pretty fast, though. As I was typing this, Apple removed the top banner altogether, preventing the customized image display. No more pranks for us.

In any case, OS X Daily pointed out that the image issue could allow malicious folks to redirect would-be Apple visitors to malware sites or other bad destinations. Even an innocent image viewer that appears within an iframe on a branded page can cause problems; that's what the folks at Wired found out last January, when someone took advantage of their image tool to post a hoax "Steve Jobs had a heart attack" news story.

Props to Apple's web development team, though, for taking this down within the ten minutes it took me to finish the post.

Categories

Hacks iTunes Apple

Our friends over at OS X Daily passed along their story noting that Apple's site for iTunes Affiliates was vulnerable to a cross-site URL...
 

Add a Comment

*0 / 3000 Character Maximum

4 Comments

Filter by:
Daryl

@manthano - the windows phone ad is for Microsoft and it looks like they are rotating a few different ads for AT&T and Verizon phones.

November 03 2009 at 10:16 PM Report abuse rate up rate down Reply
manthano

whoops.. saw it again, not for AT&T, it's for Verizon

November 03 2009 at 10:02 PM Report abuse rate up rate down Reply
manthano

speaking of top banner ads, one of the ones currently rotating on this site is for AT&T with "Windows Phone" written large... thought that was kinda funny

November 03 2009 at 9:51 PM Report abuse rate up rate down Reply
Stagueve

It was much better with this code at the end (ad a link into the text) ;)

[...] &albumName=BLOG_TITLE

November 03 2009 at 8:14 PM Report abuse rate up rate down Reply
Buy an ad here

Hot Apps on TUAW

Tweets

© 2012 AOL Inc. All Rights Reserved.