Hi All,<br><br>I have found url redirection vulnerability on <a href="http://www.orkut.com">www.orkut.com</a>.<br><br>If a user clicks on a malicious link he/she will redirect to an attackers website. The attacker can capture the valid username,password and then redirect a user to original orkut website.
<br><br>Proof Of Concept:<br><br>Original Link:<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fwww.orkut.com%2F</a><br><br>Maliciously Crafted Link:
<br><br><a href="https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com">https://www.orkut.com/GLogin.aspx?done=http%3A%2F%2Fattackers_website.com</a><br><br><br>--<br>Kishor Sonawane<br><a href="mailto:keyshor@gmail.com">
keyshor@gmail.com</a>