Saturday, September 25, 2010

Orkut Gets Flooded with ‘Bom Sabado’ Scraps

If you are amongst the few who still give a damn about Orkut, you might have noticed something fishy going on over the past few hours. A large number of users are randomly flooding their friend’s scrapbooks (Orkut’s equivalent of Facebook Wall) with the following message:



It doesn’t take a genius to figure out that the “Bom Sabado!” messages are automatically generated by a script. However, it is not clear if this is simply a script exploiting vulnerability in Orkut, or have the accounts sending the automated scraps been compromised.

If you are amongst those affected, it’s highly recommended that you follow the steps highlighted below:

* Switch to the “older version” of Orkut.
* Log out of Orkut.
* Clean your browser’s cache and cookies.
* Log in and change your password and security question.

If you haven’t been affected yet, it is strongly advised that you avoid Orkut until the issue has been resolved. Some ve managed to trigger the same exploit while researching this article. Recently other high profile websites like Twitter and YouTube also fell victim to XSS attacks.


Update 1: The worm appears to have originated in Brazil, where Orkut is still exceptionally popular. Many of the affected users are noticing the Brazilian flag on their status messages. Additionally, the word ‘Bom Sabado’ means ‘Good Saturday’ in Portuguese, which is the official language of Brazil. We are still awaiting an official response from Google.
Update 2: ‘Bom Sabado’ is now trending on Google.



Update3:The Bom Sabado worm flooding scrapbooks and also it seems to be adding affected Orkuteers to new Orkut groups. Orkut Officials and Security Professionals advised users not to Log in Orkut until they clean the Worm. Orkut has updated it’s features 3 months and it’s not the first time Orkut got affected by this kind of Worms.

If you’ve logged into Orkut, Just clear you cache/cookies and change your Orkut password asap from

www.google.com/accounts.

No comments:

Post a Comment

DISCLAIMER

DISCLAIMER:None of the files shown here are actually hosted by the blogger. The links are taken from other sites. The administrator of this blog cannot be held responsible for what links were containing. You may not use this blog to distribute or download any material when you do not have the legal rights to do so. It is your own responsibility to adhere to these terms. This blog and files are here for display purposes only and SHOULD NOT BE DOWNLOADED OR VIEWED WHATSOEVER! If you are affiliated with any government, or ANTI-Piracy group or any other related group or were formally a worker of one you CANNOT enter this , or cannot access any of the files linked on it. If you enter this blog you are not agreeing to these terms and you are violating code 431.322.12 of the Internet Privacy Act signed by Bill Clinton in 1995 and that means that you cannot + threaten our ISP(s) or any person(s) or company storing these files, cannot prosecute any person(s) affiliated with this blog which includes family, friends or individuals who run or enter this blog.