<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Orkut XSS Worm</title>
	<atom:link href="http://www.gnucitizen.org/blog/the-orkut-xss-worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: hanush</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-124296</link>
		<dc:creator>hanush</dc:creator>
		<pubDate>Sun, 09 Nov 2008 19:43:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-124296</guid>
		<description>How can i put ths script as scrap. i just got ths as a scrap in orkut from a frnd of mine.</description>
		<content:encoded><![CDATA[<p>How can i put ths script as scrap. i just got ths as a scrap in orkut from a frnd of mine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Orkut Latest XSS Worm; and what it means for Indian Orkuteers &#124; Code in my Bug!!!</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-121044</link>
		<dc:creator>Orkut Latest XSS Worm; and what it means for Indian Orkuteers &#124; Code in my Bug!!!</dc:creator>
		<pubDate>Wed, 07 May 2008 09:37:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-121044</guid>
		<description>[...] Slackers (Social n/w worm, or no). Anyhoo. This incident has already been reported by a number of bloggers, so I won&#8217;t dive into the technical details. However, this worm seems to be harmless and [...]</description>
		<content:encoded><![CDATA[<p>[...] Slackers (Social n/w worm, or no). Anyhoo. This incident has already been reported by a number of bloggers, so I won&#8217;t dive into the technical details. However, this worm seems to be harmless and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cristiano</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-118810</link>
		<dc:creator>cristiano</dc:creator>
		<pubDate>Mon, 14 Apr 2008 16:53:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-118810</guid>
		<description>&lt;pre&gt;&lt;code&gt;var flashWriter = new _SWFObject(&#039;http://www.orkut.com/GLogin.aspx?cmd=logout&#039;, &#039;77299695&#039;, &#039;300&#039;, &#039;300&#039;, &#039;9&#039;, &#039;#FFFFFF&#039;, &#039;autohigh&#039;, &#039;&#039;, &#039;&#039;, &#039;77299695&#039;); flashWriter._addParam(&#039;wmode&#039;, &#039;transparent&#039;); flashWriter._addParam(&#039;allowNetworking&#039;, &#039;internal&#039;); flashWriter._addParam(&#039;allowScriptAccess&#039;, &#039;never&#039;); flashWriter._setAttribute(&#039;style&#039;, &#039;&#039;); flashWriter._write(&#039;flashDiv77299695&#039;);&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<pre><code>var flashWriter = new _SWFObject('http://www.orkut.com/GLogin.aspx?cmd=logout', '77299695', '300', '300', '9', '#FFFFFF', 'autohigh', '', '', '77299695'); flashWriter._addParam('wmode', 'transparent'); flashWriter._addParam('allowNetworking', 'internal'); flashWriter._addParam('allowScriptAccess', 'never'); flashWriter._setAttribute('style', ''); flashWriter._write('flashDiv77299695');</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89874</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Fri, 21 Dec 2007 20:28:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89874</guid>
		<description>that code is packed with dean edwards javascript packer. if anyone needs any help deciphering what it does I wrote an article on defeating that packer, you can find it here: 

http://yaisb.blogspot.com/2006/10/defeating-dean-edwards-javascript.html</description>
		<content:encoded><![CDATA[<p>that code is packed with dean edwards javascript packer. if anyone needs any help deciphering what it does I wrote an article on defeating that packer, you can find it here: </p>
<p><a href="http://yaisb.blogspot.com/2006/10/defeating-dean-edwards-javascript.html" rel="nofollow">http://yaisb.blogspot.com/2006.....cript.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ix</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89413</link>
		<dc:creator>Ix</dc:creator>
		<pubDate>Thu, 20 Dec 2007 19:43:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89413</guid>
		<description>Almost 660 thousand hit by this, unless some people joined the group without being infected... Anyone know how long it was out in the wild before it was fixed? I&#039;ve only heard that it&#039;s been fixed but nothing on how long it took, and it would be nice to have a time amount to compare to the 659154 members.

Guess the good news is it was just a proof and not an actual attack, else life would be bad for those members right now, and nothing can wreck the holiday season like identity theft and its other related problems.</description>
		<content:encoded><![CDATA[<p>Almost 660 thousand hit by this, unless some people joined the group without being infected&#8230; Anyone know how long it was out in the wild before it was fixed? I&#8217;ve only heard that it&#8217;s been fixed but nothing on how long it took, and it would be nice to have a time amount to compare to the 659154 members.</p>
<p>Guess the good news is it was just a proof and not an actual attack, else life would be bad for those members right now, and nothing can wreck the holiday season like identity theft and its other related problems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raaka!</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89391</link>
		<dc:creator>Raaka!</dc:creator>
		<pubDate>Thu, 20 Dec 2007 18:40:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89391</guid>
		<description>&lt;pre&gt;&lt;code&gt;var flashWriter = new _SWFObject(&#039;http://www.orkut.com/GLogin.aspx?cmd=logout&#039;, &#039;77299695&#039;, &#039;300&#039;, &#039;300&#039;, &#039;9&#039;, &#039;#FFFFFF&#039;, &#039;autohigh&#039;, &#039;&#039;, &#039;&#039;, &#039;77299695&#039;); flashWriter._addParam(&#039;wmode&#039;, &#039;transparent&#039;); flashWriter._addParam(&#039;allowNetworking&#039;, &#039;internal&#039;); flashWriter._addParam(&#039;allowScriptAccess&#039;, &#039;never&#039;); flashWriter._setAttribute(&#039;style&#039;, &#039;&#039;); flashWriter._write(&#039;flashDiv77299695&#039;);&lt;/code&gt;&lt;/pre&gt;

seen this ?</description>
		<content:encoded><![CDATA[<pre><code>var flashWriter = new _SWFObject('http://www.orkut.com/GLogin.aspx?cmd=logout', '77299695', '300', '300', '9', '#FFFFFF', 'autohigh', '', '', '77299695'); flashWriter._addParam('wmode', 'transparent'); flashWriter._addParam('allowNetworking', 'internal'); flashWriter._addParam('allowScriptAccess', 'never'); flashWriter._setAttribute('style', ''); flashWriter._write('flashDiv77299695');</code></pre>
<p>seen this ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: December 20th</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89291</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: December 20th</dc:creator>
		<pubDate>Thu, 20 Dec 2007 13:37:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89291</guid>
		<description>[...] The Orkut XSS Worm (source for the worm is posted as well) [...]</description>
		<content:encoded><![CDATA[<p>[...] The Orkut XSS Worm (source for the worm is posted as well) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Orkut Latest XSS Worm; and what it means for Indian Orkuteers &#171; Hey! There is Code in my BUG!</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89270</link>
		<dc:creator>Orkut Latest XSS Worm; and what it means for Indian Orkuteers &#171; Hey! There is Code in my BUG!</dc:creator>
		<pubDate>Thu, 20 Dec 2007 12:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89270</guid>
		<description>[...] Slackers (Social n/w worm, or no). Anyhoo. This incident has already been reported by a number of bloggers, so I won&#8217;t dive into the technical details. However, this worm seems to be harmless and [...]</description>
		<content:encoded><![CDATA[<p>[...] Slackers (Social n/w worm, or no). Anyhoo. This incident has already been reported by a number of bloggers, so I won&#8217;t dive into the technical details. However, this worm seems to be harmless and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-89010</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 19 Dec 2007 22:01:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-89010</guid>
		<description>well, the worm wasn&#039;t anything special and I guess tis is the good thing. :) if it was armed with some exploits simple channeled via MPack or WebAttacker, the casualties would have been a lot more.</description>
		<content:encoded><![CDATA[<p>well, the worm wasn&#8217;t anything special and I guess tis is the good thing. :) if it was armed with some exploits simple channeled via MPack or WebAttacker, the casualties would have been a lot more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Psychlo</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-88933</link>
		<dc:creator>Psychlo</dc:creator>
		<pubDate>Wed, 19 Dec 2007 18:39:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-88933</guid>
		<description>the blog.. cut my code.. sry...</description>
		<content:encoded><![CDATA[<p>the blog.. cut my code.. sry&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Psychlo</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-88932</link>
		<dc:creator>Psychlo</dc:creator>
		<pubDate>Wed, 19 Dec 2007 18:38:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-88932</guid>
		<description>brazilians are the best asuhs (just kiddin&#039;..).. actually this was corrected today 19/12/07 and it doesn&#039;t infected really because the &quot;virus&quot; just added people into a community... the possibilities of joinning vulnerabilities could cause a bigger damage...

but now it&#039;s already fixed..</description>
		<content:encoded><![CDATA[<p>brazilians are the best asuhs (just kiddin&#8217;..).. actually this was corrected today 19/12/07 and it doesn&#8217;t infected really because the &#8220;virus&#8221; just added people into a community&#8230; the possibilities of joinning vulnerabilities could cause a bigger damage&#8230;</p>
<p>but now it&#8217;s already fixed..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tarun</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-88923</link>
		<dc:creator>Tarun</dc:creator>
		<pubDate>Wed, 19 Dec 2007 18:15:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-88923</guid>
		<description>Great Effort By yOU !!!tHX</description>
		<content:encoded><![CDATA[<p>Great Effort By yOU !!!tHX</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ICMPECHO &#187; Blog Archive &#187; Orkut XSS worm infected 400,000 users</title>
		<link>http://www.gnucitizen.org/blog/the-orkut-xss-worm/comment-page-1/#comment-88801</link>
		<dc:creator>ICMPECHO &#187; Blog Archive &#187; Orkut XSS worm infected 400,000 users</dc:creator>
		<pubDate>Wed, 19 Dec 2007 12:56:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/the-orkut-xss-worm#comment-88801</guid>
		<description>[...] more information, including source code for the virus, see: Antrix.net or GNUCITIZEN&#8217;s posts on the [...]</description>
		<content:encoded><![CDATA[<p>[...] more information, including source code for the virus, see: Antrix.net or GNUCITIZEN&#8217;s posts on the [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
