Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Worm Squirms Through Google's Orkut  (Read 3940 times)

0 Members and 1 Guest are viewing this topic.

quaxo

    Topic Starter


    Guru
  • Thanked: 127
    • Yes
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 11
Worm Squirms Through Google's Orkut
« on: December 21, 2007, 09:38:39 AM »
From PC Magazine:

A fast moving worm is squirming though Google's Orkut social network, adding hundreds of thousands of users to an Orkut community created by a Brazilian hacker.

The worm, which first appeared on Dec. 19, has been spreading through Orkut's Scrapbook system at a rapid pace, infecting more than 650,000 users in the space of a few hours.

According to an alert from anti-virus specialist Trend Micro, infection starts when an Orkut user is sent an e-mail telling them that they have a new Scrapbook entry.

Logging into Orkut, the victim is greeted with Portuguese-language text that reads: "2008 vem ai… que ele comece mto bem para vc." This translates to "2008 is coming…I wish that it begins quite well for you".

No interaction is necessary. Simply looking at the scrap starts the infection sequence," says Trend Micro researcher Robert McArdle.

Once the scrap is viewed, it deletes itself and the victim is automatically added to the "Infectados pelo Vírus do Orkut" community.

Once a user becomes infected, the infected account downloads and executes an embedded Javascript that sends a copy of the original Scrapbook post to all the victim's contacts.

According to McAfee researcher Vinay Mahadik, the worm is abusing the ability to add JavaScript content to Orkut Scrapbook entries, a feature that was only recently introduced by Google.

"This clearly illustrates the issue with allowing rich-content on social/professional networking sites, and not sanitizing it enough," Mahadik said in an entry on the McAfee Avert Labs blog.

This is the second major worm attack to take aim at a popular social network. In October 2005, the Samy worm used cross-site scripting techniques to spread through MySpace, infecting more than a million users in less than a day.

Computer Hope Admin

  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Re: Worm Squirms Through Google's Orkut
« Reply #1 on: December 28, 2007, 12:27:03 AM »
Appreciate the link. However, in the future please also post a URL to where you're getting news stories.

Link: http://news.yahoo.com/s/zd/20071219/tc_zd/222106
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein