Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12/19/2007
06:05 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Google's Orkut Social Network Hacked

Hundreds of thousands of users infected by XSS worm hidden in messages from 'friends'

A fast-moving cross-site scripting worm spread overnight through Google's Orkut social network, infecting users who viewed the emails or Orkut messages carrying its payload. The victims didn't even have to click on a link to be infected.

The worm, which used Flash-based JavaScript malware and took advantage of an XSS vulnerability in Orkut, added the victims to its rogue Orkut community, reportedly called "Infectados pelo Virus do Orkut," which at one point today had captured hundreds of thousands of involuntary members.

Scraps, or message posts to an Orkut user's profile, were the main culprit. Victims either got alerts from Orkut that they had a new entry to their scrapbook, or received emails from other Orkut friends who also had been infected. The worm was adding members to its rogue Orkut community at a rate of about 100 per minute at one time during the attack.

Orkut fixed the XSS bug earlier today, but according to OrkutPlus, a security community within the social network, the vulnerability was still active in Orkut's so-called sandbox profiles as of this posting. Google's Orkut sandboxes are closed "containers" for Orkut members, such as developers testing out applications.

The hacker behind the attack appears to have unleashed the worm to prove a point: to show how easy it is to use JavaScript and XSS to infect multiple users quickly. The attacker wrote a message in Portuguese on the rogue community site -- translated, it says: "This just to show how orkut may be dangerous, you came up here without clicking absolutely no link malicious, everything was done reading scraps." The message also said that no data was stolen in the attack.

Security experts say there was no malicious activity associated with the worm -- mostly it just was an annoyance to the infected users and their friends that caught the worm from them. "It's just a proof-of-concept, but had it been real, it could have harvested hundreds of thousands of Google accounts," says one researcher who was infected by the attack. "The attack didn't do anything malicious; it was there to prove a point. All it did was join you to a specific Orkut group."

Researcher David Maynor, CTO of Errata Security, says he got multiple Orkut-related email messages from a fellow researcher, but didn't open them and wasn't infected. He says the messages looked suspicious: "It was completely unsolicited, plus I got more than one in a very short [period] of time," Maynor says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Google (Nasdaq: GOOG)
  • Errata Security

    Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 9/21/2020
    Hacking Yourself: Marie Moe and Pacemaker Security
    Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
    Startup Aims to Map and Track All the IT and Security Things
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    Special Report: Computing's New Normal
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    How IT Security Organizations are Attacking the Cybersecurity Problem
    How IT Security Organizations are Attacking the Cybersecurity Problem
    The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-15222
    PUBLISHED: 2020-09-24
    In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "private_key_jwt", OpenId specification say...
    CVE-2020-15223
    PUBLISHED: 2020-09-24
    In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lead to unexpected 200 status codes indicating successful revocation while the token is still valid. Whether an attacke...
    CVE-2020-12842
    PUBLISHED: 2020-09-24
    ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
    CVE-2020-12843
    PUBLISHED: 2020-09-24
    ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.
    CVE-2020-13119
    PUBLISHED: 2020-09-24
    ismartgate PRO 1.5.9 is vulnerable to clickjacking.