exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

orkutShortcut.txt

orkutShortcut.txt
Posted Sep 8, 2006
Authored by Kishor Sonawane

Orkut.com suffers from a URL redirection vulnerability.

tags | exploit
SHA-256 | cd071a3edada5b89059b752e1871a54bf8cced21e63a44d289578dd90593e434

orkutShortcut.txt

Change Mirror Download
------=_Part_140691_16107831.1157619933640
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Hi All,

I have found url redirection vulnerability on www.orkut.com.

If a user clicks on a malicious link he/she will redirect to an attackers
website. The attacker can capture the valid username,password and then
redirect a user to original orkut website.

Proof Of Concept:

Original Link:

https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F

Maliciously Crafted Link:

https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com


--
Kishor Sonawane
keyshor@gmail.com

------=_Part_140691_16107831.1157619933640
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Hi All,<br><br>I have found url redirection vulnerability on <a href="http://www.orkut.com">www.orkut.com</a>.<br><br>If a user clicks on a malicious link he/she will redirect to an attackers website. The attacker can capture the valid username,password and then redirect a user to original orkut website.
<br><br>Proof Of Concept:<br><br>Original Link:<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F</a><br><br>Maliciously Crafted Link:
<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com</a><br><br><br>--<br>Kishor Sonawane<br><a href="mailto:keyshor@gmail.com">
keyshor@gmail.com</a>

------=_Part_140691_16107831.1157619933640--

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close