Blog Archive

Wednesday 30 June 2010

More Orkut fun with Javascript recharge pages

Here’s another one of those “paste Javascript into your browser” scams that wants to make significant changes to the appearance of your Orkut account. The site in question here is 500-rs-recharge(dot)minhahomepage(dot)com.

charge my phone
Click to Enlarge

It’s just out of shot, but there’s a little “How many people are on this site” doodah (technical term) at the bottom of the page which veered between around 35 and 60 visitors while I was there.

Will we get some more Javascript code to paste into the browser? Yep.

javascript charging

This one gives you the usual popup about the fact that your “recharge” is on the way, while making some updates to your Orkut page.

charger popup
Click to Enlarge

“You’ll have your free recharge in 24 hours”. Funnily enough, it’s been 24 hours since the first attempt at running Javascript from the original page and I don’t have any recharging action taking place! Anyway, you’re taken to this URL:

500-rs-recharge(dot)minhapagina(dot)info

The website refuses to load for me at the moment, but it has been submitted to PhishTank by somebody so we’ll have to wait and see if it turns out to be a Phish. I certainly wouldn’t advise logging in on there given what we’ve seen so far, though.

If we take a look at the test profile, there are now a whole bunch of random people staring out at me from the “Friends” section:

charging my friends
Click to Enlarge

Even better, take a look at my “About” section:

about me?

Click to Enlarge

“Free recharge version of Orkut, this version was introduced to all Orkut users as a gift from Google services”.

Uh…call me suspicious, but I’m going to chalk this one up as a “not buy”.

Christopher Boyd

No comments:

Post a Comment