------=_Part_140691_16107831.1157619933640
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi All,
I have found url redirection vulnerability on www.orkut.com.
If a user clicks on a malicious link he/she will redirect to an attackers
website. The attacker can capture the valid username,password and then
redirect a user to original orkut website.
Proof Of Concept:
Original Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F
Maliciously Crafted Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com
--
Kishor Sonawane
keyshor@gmail.com
------=_Part_140691_16107831.1157619933640
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi All,
I have found url redirection vulnerability on www.orkut.com.
If a user clicks on a malicious link he/she will redirect to an attackers website. The attacker can capture the valid username,password and then redirect a user to original orkut website.
Proof Of Concept:
Original Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F
Maliciously Crafted Link:
https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com
--
Kishor Sonawane
keyshor@gmail.com
------=_Part_140691_16107831.1157619933640--