R E L A T E D   C O N T E N T
ADVERTISEMENT

Orkut worm hits 700,000 users

Infection thrives on Google social network

Shaun Nichols in California, vnunet.com 21 Dec 2007
ADVERTISEMENT

A fast-moving worm has infected more than 700,000 users on Google's Orkut social network in just 24 hours.

The Portuguese language attack exploited a vulnerability in Orkut's scrapbook feature to post malicious JavaScript code on a user's page.

On viewing the scrapbook post, the code performed the exploit and downloaded a .js file to the user's machine.

The worm then took control of the user's account, sending out copies of itself to all of the user's friends and joining a group called 'Infectados pelo Vírus do Orkut', which translates as 'Infected by Orkut virus'.

The worm does not appear to download any other malicious programs. Security experts said yesterday that the malicious code has been removed from users' pages and the worm has been taken offline.

Symantec researcher Umesh Wanve said that, although the attack was largely benevolent, it is worrisome because it was launched simply by loading the user's Orkut profile.

"This worm illustrates how a simple script injection exploit could affect a large social networking site," wrote Wanve in a company blog.

"This worm could have been used for other malicious purposes, such as stealing cookies, exploiting other vulnerabilities or stealing sensitive data."

McAfee researcher Vinay Mahadik expressed similar concerns. "This clearly illustrates the issue with allowing rich content on social/professional networking sites, and not sanitising it enough," he wrote on a company blog.

"The ability to add Flash/JavaScript content to Orkut scraps was only recently introduced."

See also:

Costing victims an average of $5,000  20 Dec 2007
14 suspects arrested on money laundering charges  21 Dec 2007
Malware redirects host file  19 Dec 2007
FacebookAdult site operator named in hacking suit  19 Dec 2007
Primary threat to online shoppers this Christmas  18 Dec 2007

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities