The attack worked because the social networking site allowed users to embed Flash content in their scrap posts.
Google says it has repaired a security issue in its Orkut social networking site that allowed a worm to propagate among at least 400,000 Orkut users.
"Google takes the security of our users very seriously," a company spokesperson said in an e-mail Wednesday evening. "We worked quickly to implement a fix for the issue recently reported in Orkut. We also took steps to help prevent similar problems in the future. Service to Orkut was not disrupted during this time."
Orkut, Google's first pass at social networking, was launched in January 2004 and named after its creator and Google employee, Orkut Buyukkokten. The site is reported to have in excess of 67 million registered users overall. By comparison, MySpace boasts 110 million users.
On Wednesday afternoon, Trend Micro antivirus engineer Robert McArdle published a blog entry warning that a worm was replicating itself across Orkut using a Flash object that invokes malicious JavaScipt code.
According to McArdle, the worm was a proof-of-concept attack. "The possible implications of a more malicious attack in the future however are much more worrying," he said.
A number of security firms and organizations have warned that social networking sites are likely to be exploited more frequently in 2008. "Social networking is a new risk," said GetSafe Online, a U.K. security organization backed by the government and tech companies, in conjunction with a November press event. "Twenty-five percent of people surveyed shared confidential information with strangers on social networking sites."
The Agile ArchiveWhen it comes to managing data, donít look at backup and archiving systems as burdens and cost centers. A well-designed archive can enhance data protection and restores, ease search and e-discovery efforts, and save money by intelligently moving data from expensive primary storage systems.
2014 Analytics, BI, and Information Management SurveyITís tried for years to simplify data analytics and business intelligence efforts. Have visual analysis tools and Hadoop and NoSQL databases helped? Respondents to our 2014 InformationWeek Analytics, Business Intelligence, and Information Management Survey have a mixed outlook.
InformationWeek Must Reads Oct. 21, 2014InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.