see your advertisement here
Mobile (PDA) gre ielts gpvts mrcgp mrcog mrcp mrcpath mrcpch mrcs plab toefl usmle Forums FAQ | Help

RxPG - the perfect Rx for medical Post Graduate entrance blues!
Sign In
New User? Sign Up
Sign in to access your control panel and messenger!
 

TechZone | SpiderNevi | HowTo? | Scrapbook!

    

DocIndia Forum - Site Related Discussions - Shouts - Library - Lists - Categories  

 Revision Tools: Eponyms Facts Diseases Syndromes Pathognomics Images Crammer Vocabulary PreviousPapers OSCE Busters GRE
 Features Forums Articles Downloads Mnemonics Dictionary Reviews Videos Submit Articles

ZONES>> Hot : MBBS : PrePG : MCQs : Careers : Alt+C : UK : USA : Australia : Canada : Global : OffBeat!

 [ Customise this Navigation Bar ]

Alerts - Study Partner - Answers - Seat Reviews - I See - Search Forums | Top Reads Book Shop  

 
 Home > > Forums Email this page
RxPG :: View topic - Alert: Orkut Scraps you should delete at first notice  
 
Internet - Connecting to Internet and Websites, Medical Resources on Web Forum FAQ - Hot - Unasnwered
Page 1 of 1: Alert: Orkut Scraps you should delete at first notice
Thread Info | Related Topics | Wiki Page for This Topic | Topic Tags:
Post new topic   Reply to topic   Printer-friendly version
 Page 1 of 1
Author Message
BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll Alert: Orkut Scraps you should delete at first notice 02.03.08 (3 months ago) #1

Beware of these Orkut Scraps which contain Hijacking Scripts

Here are two scraps contianing Hijacking Scripts which i have personally checked and found they are indeed malicious.
They won't steal your passwords but they will scrap all your friends with the same message, without your knowledge.
That can be considered as a "Temporary Hijack" of your Orkut Account.

---------------------------------------------------------------------------------
So Beware if you happen to get a scrap containing these messages:

icon_arrow.gif Possible Malicious Scrap No.1

This isn't a cookie stealing script but a script which leads users to a page describing about "How to make your cell phone battery last longer".
The same page has a warning saying "Never run untrusted scripts while you are logged into orkut".



click to zoom the pic

Now whats fishy about this script is the way it uses to spread.
If you copy paste this script in your address bar and press enter,
It will send mass scraps to all your friends without your knowledge!
This is a practice which is totally unacceptable.

If you happen to get this scrap from a friend, don't suspect him.
He is just another innocent victim who inadvertently helped in the spread of the scrap.
Post Options: Reply Add Forward Report New
Back to top

Top of page


BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll 02.03.08 (3 months ago) #2

icon_arrow.gif Possible Malicious Scrap No.2


click to zoom

This is another script which used to temporarily hijack the users scrapbook.
The numbers in the scrap are actually coded info,
In this link these numbers decode into a personal googlepage which contains an unknown javascript.
The same page got deleted and now a notice :
"This page violated the GooglePages Terms Of Service & Has been deleted" is present there.
Post Options: Reply Add Forward Report New
Back to top

Top of page

BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll 02.03.08 (3 months ago) #3

How to identify Scraps Containing Password Stealing Scripts?

Golden Rule: Never Run any Scripts in your browser (copy-paste-enter) while you are logged into Orkut.
Here are some screen shots of real-time password stealing scraps.
All important info have been blurred to prevent the prorogation of these scripts.





Click to Zoom

If you look at the pictures you will see that i have blurred most of the details except some specific words.

If you happen to see these words in a script in your scrapbook, take it as a Danger Sign.
These words include;
"document.cookie" or
"getCookie" or
"UID=123456722489" or
Random numbers as seen in the Screenshot in the last post or
an unknown link ending with ".js" eg: h t t p : / / a n u n k n o w n l i n k . j s.

These Scripts are potential Cookie Stealing / Hacking / Scrapbook Flooding Scripts and should never be run while u are logged onto orkut.

If you have already ran these scripts by mistake, change your Password as early as possible.
Post Options: Reply Add Forward Report New
Back to top

Top of page

BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll 02.03.08 (3 months ago) #4

Password theft via Fake Log in Pages

This is another common trick Hackers(Crackers) use to steal your password.

Here's an actual password stealing attempt,


Click to Zoom

The Scrap says that some one have made a fake profile of yours & it has a link to that profile.
As per recent changes in Orkut, people can now mask links with words.
It means i can post a word namely "Click Here" and attach a link to it so that only the "Click Here" is visible.
(However the real link will always be visible in the status bar in firefox)
The link in the scrapbook is this one,



But if we look at the status bar at the bottom of the browser,



you will see that the real link leads to a website called "ovkut.com"
The Cracker has intelligently made a Fake Log in Page of orkut.com in the "Ovkut" site.
Actually this Ovkut.com is a custom page made in Google Pages.
(Google Pages allows all those who have a google account to make custom pages)
This proves that the person has purposefully made that page link look similar to the orkut link.
This is indeed a proof of his/her Evil Intentions.

So always check the real link in the statusbar before clicking on a link in a scrap.
Post Options: Reply Add Forward Report New
Back to top

Top of page

blue_marsSend an Instant Message to blue_mars  




Credits: 31739

My Scrapbook
My Reading List
3 Books

Quick Scroll 02.04.08 (3 months ago) #5

That is wonderful piece of information bgm..
Post Options: Reply Add Forward Report New
Back to top

Top of page

kausiksurSend an Instant Message to kausiksur  




Credits: 570

My Scrapbook


Quick Scroll 02.09.08 (3 months ago) #6

Thanks a lot....
Post Options: Reply Add Forward Report New
Back to top

Top of page

BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll 02.09.08 (3 months ago) #7

My Pleasure Friends,
The Scrap in the first post is spreading like wildfire in Orkut.
You may be able to see scraps like these in every single scrapbook.
So be extra careful of this particular scrap.



click to zoom
Post Options: Reply Add Forward Report New
Back to top

Top of page

pearllysunSend an Instant Message to pearllysun  




Credits: 15894

My Scrapbook
My Reading List
25 Books

Quick Scroll 02.10.08 (3 months ago) #8

BGM wrote:
My Pleasure Friends,
The Scrap in the first post is spreading like wildfire in Orkut.
You may be able to see scraps like these in every single scrapbook.
So be extra careful of this particular scrap.



click to zoom


yup one of my close friend too got the same , i warned her after seeing the same in her scrapbook , this is really dangerous .
Post Options: Reply Add Forward Report New
Back to top

Top of page

BGMSend an Instant Message to BGM  




Credits: 103020

My Scrapbook


Quick Scroll 02.10.08 (3 months ago) #9

I have seen that scrap in atleast a dozen orkut scrapbooks!
The Good thing is that it is not a Cookie Stealing Script, so those who ran those scripts are not in risk of Password Theft.
The Bad thing is that it will use your id temporarily for sending the same scrap to every single person in your friends list.
All your friends will see the scrap containing the script in your name!
Sending hundreds of Scraps in spamming and Orkut may delete the Orkut id if many hundreds of scraps are sent in a short time period.
Post Options: Reply Add Forward Report New
Back to top

Top of page

 Page 1 of 1
Thread Information  :  Email this thread  :  Printer Friendly  :  Terms of Service  
Post new topic   Reply to topic   Printer-friendly version

Related Discussion Topics
Sticky: Library: Last Day Revision Notes - 77 replies
MCCQE Part 1 Questions for Last Two Years - 159 replies
psm: vaccines, last laugh - 10 replies
Flow during last stage of expiration decreases - 9 replies
Maharashtra PGMCET 2005 - 26 replies
How to view all posts since last visit? - 3 replies
HC fixes tentative fee; May 28 last day to pay - 1 replies
latest updates of" 50% seats" - 302 replies
Last Date for Joining ......... - 3 replies
last year seat allotment - 5 replies
WOW!!!!! AT LAST KERALA FORM IS OUT - 0 replies
SIDE EFFECT OF TIMOLET -AIIMS NOV 2003 - 13 replies
Thread Options: Quick Reply  :  Start New Topic  :  Printer Friendly Version  :  Add this post to My Forum

Home -> Forums -> Internet - Connecting to Internet and Websites, Medical Resources on Web -> Alert: Orkut Scraps you should delete at first notice
Server Status: NORMAL, 215 pages served in last minute. Page generation time: 1.060 seconds



Site Maps: [Books] [News] [Forums] [Reviews] [Mnemonics]

sitemap - top30 - centuries - testimonials


About Us :: Disclaimer :: Contact Us :: Report Abuse :: Terms of Services :: Privacy Policy

Advertise with RxPG!

What is XML?

Made in India by RxPG Medical Solutions Private Limited