Orkut.com suffers from a URL redirection vulnerability.
cd071a3edada5b89059b752e1871a54bf8cced21e63a44d289578dd90593e434
------=_Part_140691_16107831.1157619933640
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi All,
I have found url redirection vulnerability on www.orkut.com.
If a user clicks on a malicious link he/she will redirect to an attackers
website. The attacker can capture the valid username,password and then
redirect a user to original orkut website.
Proof Of Concept:
Original Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F
Maliciously Crafted Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com
--
Kishor Sonawane
keyshor@gmail.com
------=_Part_140691_16107831.1157619933640
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi All,<br><br>I have found url redirection vulnerability on <a href="http://www.orkut.com">www.orkut.com</a>.<br><br>If a user clicks on a malicious link he/she will redirect to an attackers website. The attacker can capture the valid username,password and then redirect a user to original orkut website.
<br><br>Proof Of Concept:<br><br>Original Link:<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F</a><br><br>Maliciously Crafted Link:
<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com</a><br><br><br>--<br>Kishor Sonawane<br><a href="mailto:keyshor@gmail.com">
keyshor@gmail.com</a>
------=_Part_140691_16107831.1157619933640--