Sorry ,Out of course Post but it is my duty to aware you my friends
Admin please forgive me
I just copy paste here with source
New Delhi: In the second major XSS (cross-site scripting) attack on a major social networking service this week, Google owned Orkut was flooded with "Bom Sabado" scraps.
The word "Bom Sabado" means "Good Saturday" in Portuguese, which is the also the official language of Brazil, one of the last remaining Orkut bastions in the world.
The worm seems to be posting scraps with the text "Bom Sabado" and also adding affected users to new Orkut groups. Such XSS attacks have targeted Orkut in the past too.
Experts have advised users to avoid logging on to Orkut till Orkut engineers fix the hole and also not to click on any suspicious links. Orkut had just last month announced new updates to the website.
Earlier this week, the popular microblogging website Twitter was also at the receiving end of an XSS exploit. The attack, which emerged and was shut down within hours Tuesday morning, involved a XSS flaw that allowed users to run JavaScript programs on other computers.
Source: Orkut attacked by 'Bom Sabado' worm - Tech News - IBNLive
Solutions:-
Follow these steps:
1. Immediately change your password and security question{ including secondary email and mobile number if they also got changed.) This will solve the problem.
2. Find out whether some communities has been joined automatically. if yeah, do remove them.
3. If your account has been completely hacked, see here:
[FAQ] - Orkut account hacked / How to get back hacked Account / Orkut Account taken over by someone. - orkut Help
4. Always remember these points :
4.1 Donot ever login to any site rather than www.orkut.com
4.2 Donot ever run any javascripts while logged into your orkut account
4.3 Never use any flooder in your account
4.4 Donot ever share your password with anyone else and keep changing your password regularly.
4.5 Donot ever click suspicious link while logged into Orkut a/c. if you are curious you can copy the link and check them in
other browser after cleaning it’s browser’s cookie and cache.
4.6 Donot ever install any suspicious script on greasemoneky and ALWAYS DIABLE THE GM before logging in to orkut.
4.7 Do your mobile verification also, so that you can get back your a/c if hacker doesn’t change the mobile number there.
orkut -
4.8 Install a good Update Ant ivirus and Anti Key logger and keep your system free from Key loggers and backdoor trojans.
4.9 Use Virtual Keyboard to enter your password for more securite. KIS 2010 provides it and there are many other V.
keyboards available.
Take a look here and follow the points given to protect your a/c:
How to protect my orkut account : Privacy Settings - Orkut Help
and
Orkut Privacy and Security Center : Privacy Settings - Orkut Help
hope this helps you…
happy Orkutting..



LinkBack URL
About LinkBacks
Reply With Quote