Breaking : Dont Click On Orkut Feeds – They Are Not at All Safe!


We will just give a brief but a Very Serious Warning to all of you. We hope Orkut will get to know this flaw in their Feeds and correct this XSS as soon as possible.

Safety Note: We (below) asking you to click on the feeds of our support profile is just an demo and is NOT any thing which could harm your profile BUT we seriously mean that clicking on feeds of other unknown profiles may result in serious damage your account – Exploiting your session cookies and gaining access to Your Orkut Account

Not Taking much time we would offer you a live demo of the flaw. Please check the feeds of our Support Profile (just a demo)

You will get an idea, if we can take you to 2-3 pages after a single click, then what actually unethical minds can do? We just have the following words to describe it – Very Dangerous

UPDATE : Orkut has fixed this XSS Hole

Gaurav DuaOrkut Guru539 Points
22, Webmaster and Businessman. Based in Jammu, J&K – India
Gaurav has written 507 Articles, posted 322 Comments.

Loading

Tags - Cross Site Scripting, Security, Tips

Leave a Reply