Forum latest

Google's Orkut Social Network Hacked
General
Written by Daniel   
Thursday, 20 December 2007 12:06
 Hundreds of thousands of users infected by XSS worm hidden in messages from 'friends'

DECEMBER 19, 2007 | 4:05 PM
By Kelly Jackson Higgins
Senior Editor, Dark Reading

A fast-moving cross-site scripting worm spread overnight through Google's Orkut social network, infecting users who viewed the emails or Orkut messages carrying its payload. The victims didn't even have to click on a link to be infected.

The worm, which used Flash-based JavaScript malware and took advantage of an XSS vulnerability in Orkut, added the victims to its rogue Orkut community, reportedly called "Infectados pelo Virus do Orkut," which at one point today had captured hundreds of thousands of involuntary members.

Scraps, or message posts to an Orkut user's profile, were the main culprit. Victims either got alerts from Orkut that they had a new entry to their scrapbook, or received emails from other Orkut friends who also had been infected. The worm was adding members to its rogue Orkut community at a rate of about 100 per minute at one time during the attack.

Orkut fixed the XSS bug earlier today, but according to OrkutPlus, a security community within the social network, the vulnerability was still active in Orkut's so-called sandbox profiles as of this posting. Google's Orkut sandboxes are closed "containers" for Orkut members, such as developers testing out applications.... More    Comment in the Forum
 

See also

None found.


Hardware | Windows | Linux | Security | Mobile Devices | Gaming
Tech Business | Editorial | General News | folding@home

Forum | Download Files

Copyright ©2001 - 2012, AOA Forums.  All rights reserved.

Alliance of Overclocking Arts

Links monetized by VigLink

Don't Click Here Don't Click Here Either