Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12/19/2007
06:05 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Google's Orkut Social Network Hacked

Hundreds of thousands of users infected by XSS worm hidden in messages from 'friends'

A fast-moving cross-site scripting worm spread overnight through Google's Orkut social network, infecting users who viewed the emails or Orkut messages carrying its payload. The victims didn't even have to click on a link to be infected.

The worm, which used Flash-based JavaScript malware and took advantage of an XSS vulnerability in Orkut, added the victims to its rogue Orkut community, reportedly called "Infectados pelo Virus do Orkut," which at one point today had captured hundreds of thousands of involuntary members.

Scraps, or message posts to an Orkut user's profile, were the main culprit. Victims either got alerts from Orkut that they had a new entry to their scrapbook, or received emails from other Orkut friends who also had been infected. The worm was adding members to its rogue Orkut community at a rate of about 100 per minute at one time during the attack.

Orkut fixed the XSS bug earlier today, but according to OrkutPlus, a security community within the social network, the vulnerability was still active in Orkut's so-called sandbox profiles as of this posting. Google's Orkut sandboxes are closed "containers" for Orkut members, such as developers testing out applications.

The hacker behind the attack appears to have unleashed the worm to prove a point: to show how easy it is to use JavaScript and XSS to infect multiple users quickly. The attacker wrote a message in Portuguese on the rogue community site -- translated, it says: "This just to show how orkut may be dangerous, you came up here without clicking absolutely no link malicious, everything was done reading scraps." The message also said that no data was stolen in the attack.

Security experts say there was no malicious activity associated with the worm -- mostly it just was an annoyance to the infected users and their friends that caught the worm from them. "It's just a proof-of-concept, but had it been real, it could have harvested hundreds of thousands of Google accounts," says one researcher who was infected by the attack. "The attack didn't do anything malicious; it was there to prove a point. All it did was join you to a specific Orkut group."

Researcher David Maynor, CTO of Errata Security, says he got multiple Orkut-related email messages from a fellow researcher, but didn't open them and wasn't infected. He says the messages looked suspicious: "It was completely unsolicited, plus I got more than one in a very short [period] of time," Maynor says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Google (Nasdaq: GOOG)
  • Errata Security

    Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 9/21/2020
    Cybersecurity Bounces Back, but Talent Still Absent
    Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
    Meet the Computer Scientist Who Helped Push for Paper Ballots
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Latest Comment: Exactly
    Current Issue
    Special Report: Computing's New Normal
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    How IT Security Organizations are Attacking the Cybersecurity Problem
    How IT Security Organizations are Attacking the Cybersecurity Problem
    The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-7734
    PUBLISHED: 2020-09-22
    All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
    CVE-2020-6564
    PUBLISHED: 2020-09-21
    Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
    CVE-2020-6565
    PUBLISHED: 2020-09-21
    Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
    CVE-2020-6566
    PUBLISHED: 2020-09-21
    Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
    CVE-2020-6567
    PUBLISHED: 2020-09-21
    Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.