New Orkut Sql Injection Creating Spam in scrapbooks

Hi..
I think social networking sites are now being attacked by hackers with scripts and code snippets,that is posing security threats to naive day to day naive users.

As reported by an Orkut user there is a script going on in Orkut that scrap your friends like this….when u execute it in your address bar.

Hi,How are you.
Do you know there was a profile in news last night.
link :- click here
JOIN ME HERE:- BANI “MTV ROADIES” GIRL
VIEW ANYONE’S LOCKED ALBUM NOW.

  • Go to the profile of which you need
    to view the album
  • Copy the javascript given below and paste
    it to your address bar where you write www.orkut.com and hit enter
  • Now wait for the images to be loaded,as it will take a few minutes.

The script that comes into play in this hack is provided to you at this page and is available for download from this link.It has a .js extension so don’t click on this link while logged-in to orkut
http://mrnoobrulez.110mb.com/orkut0.js

But do not play with this link the script in this link does the following things…

  • It sends the same scrap to all friends of victim
  • It hiddenly adds the user to 3 communities Love is in the air , Fastest community ever and Orkut
  • Displays text about basics of SQL injections

This orkut hack script is replicated very rapidly on Orkut .

Popularity: 3% [?]

About Inderjeet

Inderjeet Singh is the founder and main author of Tech2view.com and writes about Technology, SEO, Social Media, Ways to Make Money Online and Security on Internet. Apart from blogger, he is a professional SEO and deals in onpage/offpage optimization aspects of small business websites and blogs. You can catch him at http://twitter.com/singhinder
This entry was posted in Orkut. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>