Posted on Wednesday, December 19th, 2007 | Bookmark on del.icio.us

Orkut XSS Worm

by Jose Nazario

Overnight I got a handful of “Person X has written you a scrapbook entry” mails from Orkut, Google’s social network. Not just spams claiming to be from Orkut, and not a Phishing attack. I got suspicious, this sort of thing suggested a malware attack on Orkut (a’la the Samy XSS worm on MySpace). But, it was the middle of the night so I went to sleep. But other people had a quick look, so hats off to them.

The worm was driven by an XSS attack on Orkut, gaping holes in script insertion, and well connected users. All in all abou 400,000 users were reportedly affected.

Google reports that the hole has been closed and profiles fixed.

More information, including code dissection:

One Response | Add your own



Comment Post by: ICMPECHO » Blog Archive » Orkut XSS worm infected 400,000 users — December 19th, 2007 @ 7:14 pm EST  Reply

[…] von Stuppe - Orkut Worm Arbor Networks - Orkut XSS Worm SophosLabs - Large scale Orkut virus outbreak not cool TrendMicro - Orkut/Google worms Compromise […]

Leave a Comment