Re: [Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread Peter Dawson
add another country ..:)-   In Turkish, Orkut means "the holy meeting place." and yes, Googles Orkut was built by a Turkish Google engineer – Orkut Buyukkokten  On 9/7/06, cardoso <[EMAIL PROTECTED]> wrote: Well, so now TWO countries care about orkut stuff, Brazil and Finland ;)I think its creator,

Re: [Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread Olli Haukkovaara
Sorry guys, but this particular URL, www.orkut.com , makes usFinns smile... "Orkut" means in our language "orgasms".I just had to share this with you, please forgive me, it's almost friday night ;-)Regards, OlliOn 9/7/06, Julio Cesar Fort <[EMAIL PROTECTED]> wrote: > I have found url redirection v

Re: [Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread cardoso
Well, so now TWO countries care about orkut stuff, Brazil and Finland ;) I think its creator, Orkut Büyükkökten, had a hell of a childhood, with such name. On Thu, 7 Sep 2006 20:53:53 +0300 "Olli Haukkovaara" <[EMAIL PROTECTED]> wrote: > Sorry guys, but this particular URL, www.orkut.com , mak

Re: [Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread Julio Cesar Fort
> I have found url redirection vulnerability on www.orkut.com. Man, I don't want to disappoint you but this redirection vulnerability is pretty old and has been being used in Brazil for sometime. This vulnerability was noticed in the begining of the year, maybe, when orkut had changed its authenti

Re: [Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread Adriel Desautels
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Did you notify orkut? keyshor wrote: > Hi All, > > I have found url redirection vulnerability on www.orkut.com > . > > If a user clicks on a malicious link he/she will redirect to an > attackers website. The attacker can capture

[Full-disclosure] Orkut URL Redirection Vulnerability

2006-09-07 Thread keyshor
Hi All,I have found url redirection vulnerability on www.orkut.com.If a user clicks on a malicious link he/she will redirect to an attackers website. The attacker can capture the valid username,password and then redirect a user to original orkut website. Proof Of Concept:Original Link:https://www.o