Orkut Album Bug is Fixed. Details are here!

ADVERTISEMENTS

Few hours back, I wrote about latest orkut album bug which enabled any user to delete anyone’s photo. Looked like orkut is reading this blog as a bug open from 4 days is now fixed temporarily.

Anyway I feel its safe to unveil details now. As most of the stuff below is technical in nature, you can skip it if you want…

Where was the bug?

The bug was in EditPhotos.aspx, a program which handles orkut new album feature, editing all photos at once.

Now have a look at following URL structure…

http://www.orkut.com/EditPhotos.aspx?uid=NUM1&aid=NUM2&full=1

It takes three parameters. uid as most already know is a user id which is also in profile, scrapbook and user specific URL’s.

aid is for album id. Its relatively new and identifies each orkut album uniquely. It was introduced with the launch of album feature into orkut. Before that there was a single album only for all photos.

I don’t know more about full=1 but it has to be there in every request I observed.

How it was used?

uid is easy to get but we need aid to target an album. Also all combination of uid and aid are not valid, even if they exist separately.

So best way was to go to album first. A URL to an album is like

http://www.orkut.com/Album.aspx?uid=1545095170420763194&aid=1200558782

Now use values of uid and aid from URL like above and construct a URL for EditPhotos.aspx which is like below, in this case…

http://www.orkut.com/EditPhotos.aspx?uid=1545095170420763194&aid=1200558782&full=1

Now opening link like above just few hours back could give you EDIT access to the Tanmay’s album which we used in this example! ;-)

But what about locked or private album?

Yeah, the question is valid as in order to gain EDIT access to album you need to view them first and if album is locked, you can not view them.

Now coming back to the event when orkut launched album feature, if you remember, there was a default album created for you by orkut. All such album have aid=1. And uid is something not secret at all!

So even if a user choose to lock albums, first album could be viewed and edited! And barring one exception in my own test all locked album shown in content of first album. Of course I haven’t edited them! ;-)

What the hell is this EDIT access I am talking about?

Put in simple terms, anyone can do to your albums things you think only you could do… ;-)

Where things might went wrong?

As I mentioned in earlier post, it looked to me Orkut relayed upon authentication handled by parent program. EditPhotos.aspx have only direct link from Album.aspx. Album.aspx do authenticate a user in order to show/hide uploading option and some other features. But EditPhotos.aspx seemed to count on it, which is wrong thing to do. Every program where thing can be written back must authenticate content owner separately!

Is this bug really fixed?

One word answer is NO. But orkut has taken down EditPhotos.aspx as of now so it will come back with fix hopefully. So as of now neither you, nor anyone else can use edit all photo feature at once!

YES, the bug is fixed and EditPhotos.aspx is back. So there is nothing to worry for a while!

But I repeat, never count on orkut for your safety! :-)

Share and Enjoy:
  • Digg
  • del.icio.us
  • IndianPad
  • StumbleUpon
  • Technorati
  • YahooMyWeb
  • Furl
  • Reddit
  • Google
  • TwitThis
  • Facebook
  • Slashdot
  • SphereIt
  • blogmarks
  • MisterWong

If you like this post, you may subscribe to my RSS feed or email alerts to receive automatic updates in future! Thanks for reading... :-)

Comment RSS · TrackBack URI

16 Comments (including Pingbacks/Trackbacks) so far »

  1. #
    rishab on April 18, 2008

    Hey tell us how to see pics den ?

  2. #
    rahul on April 23, 2008

    please tell me how do i unlock the album in orkut because its a matter of my life as i have a doubt about my fiancee … so for god sake please help

  3. #
    Rahul Bansal on April 24, 2008

    @rishab
    Not possible as of now!
    The bug is fixed! :-)

  4. #
    Rahul Bansal on April 24, 2008

    @rahul
    Sorry bro, bug is fixed so no donuts as of now! :-(

    One personal suggestion…
    If you don’t trust her… better leave her. It never works without trust! :-)

  5. #
    Bajal on April 26, 2008

    Looks like the bug did get fixed after all. This is what you get now :

    Bad, bad user! No donut for you.

    You are not authorized to do the requested action.

    :D :D

  6. #
    Rahul Bansal on May 3, 2008

    @Bajal
    First sorry for late reply as I was offline on a long vacation.

    Now the bug got fixed on same day I posted this. I forgot to update this post… :-(
    Thanks for reminding… :-)

  7. #
    saurabh on June 9, 2008

    dear find new way to c album or any bug

  8. #
    blueshift on June 10, 2008

    Never knew about this. Thanks.

  9. #
    Rahul Bansal on June 12, 2008

    @Saurabh
    Man its not easy anymore… :-(
    Orkut is getting more n more secure everyday…

    @blueshift
    Your welcome buddy :-)

  10. #
    Prashant on October 11, 2008

    it will open your album for editing…..!!

  11. #
    Rahul Bansal on October 12, 2008

    @Prashant -
    It won’t… ;-) It used to but… for few days.. :-)

  12. #
    EXPTORIZ on October 24, 2008

    i found a new way to explot a album, using a sql injection , to explit the old vunarility crreating a target reponse from the codding, which will enable a temoporary acces ID while the request is been sent that temporary id will be opened untill the session has finalized which can take up to 30 seconds while having that temporary loop hole between you and the unouthorizez request, you will notice in the bar below your internt explore or the firefox page the id that gives the temporary return request, all you have to do is after getting that temporary acces you will be able to gain complete access to the end users album for a very very short time, enableing you to edit or delte pictures comments, specially on accessin the aid=1 which still the smae way with no alteration what so ever..

    GOOD Digging guys….

  13. #
    Deepak on October 28, 2008

    @EXPTORIZ -
    Buddy can you please be more clear about it??

  14. #
    vijayakumar on November 15, 2008

    I think all the bugs have been fixed, now nothing is working.

    vijay

  15. #
    Deepak Jain on November 15, 2008

    @vijayakumar -
    Yes…
    That is what Rahul have mentioned on the post.

Leave a Comment

 Name (Required)
 E-mail (Required)
 Website

Comment:

  OR Use forum if posting unrelated to this topic.
[Note: All comments will be moderated as per our comments policy.]

Subscribe without commenting


1 Trackbacks/Pingbacks

  1. New Orkut Bug Let Anyone Edit & Delete Photos of Any Orkut user [ALERT] | Welcome To Devils Workshop on April 18th, 2008