Orkut Attacked by Bom Sabado (Google update in description below)

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
3,289
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 25, 2010

UPDATE(monday)
A Google spokesperson issued the following statement: We took swift action to fix a cross-site scripting (XSS) vulnerability on orkut.com that was discovered early Saturday. We were aware of a script being used to spread messages on orkut, but our analysis of the script code did not reveal any evidence of users' accounts becoming compromised; nonetheless, the issue is now resolved. We're in the process of cleaning affected profiles, and we are studying the vulnerability to help prevent similar issues in the future.

********************************************************************************­*

The worm injects a hidden iframe containing a malicious javascript http://tptools.org/worm.js [do not click this], which steals the user cookie which contains the password in an encoded form. So the attacker do not get to know your plaintext password but can login using your credentials by impersonating using the cookie to fool the identification system.

1)So a trivial solution is to diable javascript, another solution is to disable iframes or u can take an advanced measure by blocking the domain http://tptools.org/ by editing your hosts file and redirecting it to a safe address, say 127.0.0.1

go to C:\windows\system32\drivers\etc\
There is a file named 'hosts'. By default it is read-only. Go to it properties and uncheck the tickmark beside read-only
edit it with you favourite editor.

add this line at the end of it

127.0.0.1 tptools.org

save it. and then restart your network interface. ( in simple words, just reconnect your interner connection ) and bingo!! the worm'll be useless.

2)Another Solution:
Worm Inject a hidden iframe so better avoid it use this simple firefox technique to browse securely: https://docs.google.com/document/pub?id=1AadoIcyLNdMQF8fH2P98I5GWAVoaf05YzcTY...


Hope this will work :)

Category:

People & Blogs

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (madhubani36town)

  • Google has finally responded through an official forum,they are claiming to have identified the bug that allowed this and have fixed it.

    They’re currently working on restoring the affected profiles.

    However, few people are claiming for new variants of the worm (such as ORKUT 3XPL0!T5) appear, which suggests that the underlying vulnerability is yet to be plugged.

  • The worm injects a hidden iframe containing a malicious javascript, which steals the user cookie which contains the password in an encoded form. So the attacker do not get to know your plaintext password but can login using your credentials by impersonating using the cookie to fool the identification system.

  • Use m.orkut.com to open the non html version of orkut to check your scraps.

    This is the mobile version of Orkut which is working.Check the scraps and sadly though u cant delete them.

  • Hey I have solv that probs... just clear the cookies > dont need to change password..

  • @MrKeshavnaidu but thats not the issue,issue is that if the hackers have got your password(encrypted) through cookies then you sud change that b4 smething else happens to you

  • The worm appears to have originated in Brazil, where Orkut is still exceptionally popular. Many of the affected users are noticing the Brazilian flag on their status messages. Additionally, the word ‘Bom Sabado’ means ‘Good Saturday’ in Portuguese, which is the official language of Brazil

see all

All Comments (10)

Sign In or Sign Up now to post a comment!
  • Thir is some more problum > unwanted communities have joind automatically.

    how to get ride.

  • it's a virus(worm) affected millions of accounts today!! 

  • What is this.. Bom sabado! is it a Virus or Something???

    Brasil ka Virus Lagta hai

  • bhag bhosdi...

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more