<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; orkut</title>
	<atom:link href="http://www.darknet.org.uk/tag/orkut/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Worm Spreading Fast on Google&#8217;s Orkut Social Network</title>
		<link>http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/</link>
		<comments>http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 07:23:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[googles orkut]]></category>
		<category><![CDATA[hacking-orkut]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virii]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[web based worm]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/</guid>
		<description><![CDATA[A new worm has hit Google&#8217;s Orkut and it seems to be hitting it pretty hard, it&#8217;s infected via the scrapbook feature and is adding hundreds of thousands of users, similar to the Myspace worm (Samy) that hit in October 2005. It seems to be fairly unmalicious, more of a &#8216;look at me &#8211; see [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A new worm has hit <a href="http://www.orkut.com/Home.aspx">Google&#8217;s Orkut</a> and it seems to be hitting it pretty hard, it&#8217;s infected via the scrapbook feature and is adding hundreds of thousands of users, similar to the <a href="http://namb.la/popular/tech.html">Myspace worm (Samy)</a> that hit in October 2005.</p>
<p>It seems to be fairly unmalicious, more of a &#8216;look at me &#8211; see what I can do&#8217; kind of thing. It&#8217;s certainly interested to see that social networking sites are beginning to be the focus of hackers, even if it&#8217;s not for money or stealing info..But more of a playground to test their skills.</p>
<blockquote><p>A fast moving worm is squirming though Google&#8217;s Orkut social network, adding hundreds of thousands of users to an Orkut community created by a Brazilian hacker.</p>
<p>The worm, which first appeared on Dec. 19, has been spreading through Orkut&#8217;s Scrapbook system at a rapid pace, infecting more than 650,000 users in the space of a few hours.</p>
<p>According to an alert from anti-virus specialist Trend Micro, infection starts when an Orkut user is sent an e-mail telling them that they have a new Scrapbook entry. </p></blockquote>
<p>I guess you can avoid it by not reading any scraps, or using something like <a href="http://noscript.net/">NoScript</a> &#8211; which would remove the danger of the JavaScript. But again it comes back to the same old thing, how many average users would even know what NoScript is?</p>
<blockquote><p>Logging into Orkut, the victim is greeted with Portuguese-language text that reads: &#8220;2008 vem ai… que ele comece mto bem para vc.&#8221; This translates to &#8220;2008 is coming…I wish that it begins quite well for you&#8221;.</p>
<p>No interaction is necessary. Simply looking at the scrap starts the infection sequence,&#8221; says Trend Micro researcher Robert McArdle.</p>
<p>Once the scrap is viewed, it deletes itself and the victim is automatically added to the &#8220;Infectados pelo Vírus do Orkut&#8221; community.</p>
<p>Once a user becomes infected, the infected account downloads and executes an embedded Javascript that sends a copy of the original Scrapbook post to all the victim&#8217;s contacts.</p></blockquote>
<p>But yes indeed, it shows the danger of allowing rich user content sanitizing it properly. Haven&#8217;t they learned their lessons from what happened at MySpace?</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/article2/0,1759,2237733,00.asp?kc=EWRSS03129TX1K0000614">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D771+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;t=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;title=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;title=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;title=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/&amp;title=Worm+Spreading+Fast+on+Google%E2%80%99s+Orkut+Social+Network" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F12%2Fworm-spreading-fast-on-googles-orkut-social-network%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/12/worm-spreading-fast-on-googles-orkut-social-network/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Google&#8217;s Orkut Hit by Data Stealing Worm &#8211; Mw.Orc</title>
		<link>http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/</link>
		<comments>http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/#comments</comments>
		<pubDate>Wed, 21 Jun 2006 07:57:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[data-security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-orkut]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[orkut-worm]]></category>
		<category><![CDATA[sophos]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/</guid>
		<description><![CDATA[So just a few days about there was a new MSN Worm &#8211; BlackAngel.B, before that the Yahoo! e-mail worm, long before that of course the MySpace worm and a few others not notable enough to mention. And of course plenty of nasty Trojans. A new Internet worm capable of stealing bank details and other [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So just a few days about there was a new <a href="http://www.darknet.org.uk/2006/06/new-msn-worm-hitting-users-blackangelb/">MSN Worm &#8211; BlackAngel.B</a>, before that the Yahoo! e-mail worm, long before that of course the MySpace worm and a few others not notable enough to mention.</p>
<p>And of course plenty of nasty <a href="http://www.darknet.org.uk/tag/trojans">Trojans</a>.</p>
<blockquote><p>A new Internet worm capable of stealing bank details and other personal data from users is circulating via Orkut, Google Inc.&#8217;s social networking service, a computer security company warned on Monday.</p>
<p>Instant-messaging service provider FaceTime Communications said its software security lab had detected the spread of the electronic virus, the third such threat to disseminate itself via messages posted on Orkut users personal Web pages.</p>
<p>Google&#8217;s service, while available globally, is wildly popular among Brazilians which make up the bulk of its users.</p>
<p>The malicious program, dubbed by FaceTime as &#8220;MW.Orc,&#8221; works its way onto users&#8217; personal computers when they click on infected links on Orkut scrapbook pages. The link is followed by a message in Portuguese that entices the user to click.</p></blockquote>
<p>It seems this is not the first time Orkut has been hit, this one however goes after personal details of a more valuable nature.</p>
<blockquote><p>Once the link is activated, a file is uploaded to the PC, according to a description of how the worm works contained in a statement by the Foster City, California-based company.</p>
<p>When infected Orkut users using Microsoft Corp.&#8217;s widely used Windows XP operating system to find personal files on their PCs through their &#8220;My Computer&#8221; icon, that triggers an e-mail back to the creator of MW.Orc creator filled with personal information stored on the PC, FaceTime said.</p></blockquote>
<p>The earlier attempt seemed to be more of a phishing affair.</p>
<blockquote><p>The new threat to Orkut follows an earlier worm, Banker-BWD, which was uncovered by Sophos, an anti-virus company.</p>
<p>That malicious software also disseminated itself through Orkut&#8217;s scrapbook pages, but automatically transferred the victims to fake Web pages of banks in order to entice the users to enter personal data that can then be stolen by the hackers.</p></blockquote>
<p>People are getting pretty handy with all this HTML worm business, I&#8217;m impressed.</p>
<p></p>
<p>Source: <a href="http://today.reuters.com/stocks/QuoteCompanyNewsArticle.aspx?view=CN&#038;storyID=2006-06-19T211345Z_01_N19197360_RTRIDST_0_TECH-ORKUT-VIRUS.XML&#038;rpc=66">Reuters</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D260+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;t=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;title=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;title=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;title=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/&amp;title=Google%E2%80%99s+Orkut+Hit+by+Data+Stealing+Worm+%E2%80%93+Mw.Orc" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F06%2Fgoogles-orkut-hit-by-data-stealing-worm-mworc%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/06/googles-orkut-hit-by-data-stealing-worm-mworc/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

