Security Risk in Orkut

Status
Not open for further replies.

sganesh

Journeyman
Security Threats in Orkut

Breaking - XSS in Scrapbook . If You Open Your Scrapbook You Can Be Hacked!
This is true. You can now get hacked even if you try to read your scraps. There is an XSS prevailing in the scrapbook, which allows the execution of malicious script, which can preform following actions:

* Stealing your cookies
* Logging you out and redirecting you to a fake page (screenshot)
* Logging you out and redirecting you to a
page which automatically installs keylogger, viruses in your computer system.

Solution-> The latest series of firefox comes with an inbuilt feature of httpOnly which encrypts your cookies so that the information in the cookie cannot be read. This may result to be a boon for orkut users.
Article read from
*orkutplus.blogspot.com/2007/12/breaking-xss-in-scrapbook-if-you-open.html
 
OP
sganesh

sganesh

Journeyman
Eventhough google claims orkut to be safe,Hackers are growing their strength day by day.
The real problem is,orkut doesnt check scripts which are good or malicious to execute
 

phreak0ut

The Thread Killer >:)
Time to move to FF for me till the hole is plugged. I hope Opera also has good protection for this.
 

Voldy

The Dark lord
oh boy its good for me that iam not so much visiting that site :D
Thanks for the info buddy nice job ! to alert the visiters.
 
OP
sganesh

sganesh

Journeyman
i think its better to use firefox,it has got many awards as most secure web browser,
me haven't tried opera,How is it?
 
Status
Not open for further replies.
Top Bottom