Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Latest Yahoo! Vulnerability Appears To Be A Moving Target For Messenger
tansqrx
post Feb 7 2008, 11:44 PM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 503
Joined: 25-April 05
Member No.: 4,374



I have been aware of the latest Yahoo! Jukebox and until recently Messenger exploits for about a week. Starting on the 3rd of February, three critical vulnerabilities were posted for datagrid.dll and mediagrid.dll which are part of the Yahoo! Jukebox offering (http://www.securityfocus.com/bid/27578, http://www.securityfocus.com/bid/27579, http://www.securityfocus.com/bid/27590). The reason that I waited so long to post this is because the details were inconsistent and it didn’t add up to me. The versions of Messenger that were listed as vulnerable are absolutely ancient with the most recent being version 5.x. I tried to find similar DLLs on my system (I have 9.0 beta) but they were simply not present even with the Yahoo! music plug-in. This leads me to believe that this exploit is a non-issue and doesn’t really deserve any attention besides possible research material.

As of the 7th of February the postings from SecurityFocus have been changed to reflect that only Yahoo! Music Jukebox 2.2 is affected. What appeared to be a great exploit for Messenger has become nothing.
Go to the top of the page
 
+Quote Post
yordan
post Feb 8 2008, 12:43 PM
Post #2


Way Out Of Control - You need a life :)
Group Icon

Group: [MODERATOR]
Posts: 1,897
Joined: 16-August 05
Member No.: 7,896



QUOTE
this exploit is a non-issue

Except, maybe, for people still having this old version of Messenger ?
Here is an opportunity to verify that : do people around here still have old machines connected to the internet ? Do you have these files on your machines ?
Personnally, I recommend using old machines (obviously sold with old Windows versions) without any important data as surfing machines, leaving their important machines off the Internet. So, such old machines will probably have this exploit.
Go to the top of the page
 
+Quote Post
tansqrx
post Feb 8 2008, 09:32 PM
Post #3


Super Member
Group Icon

Group: [HOSTED]
Posts: 503
Joined: 25-April 05
Member No.: 4,374



Perhaps but Yahoo! issues mandatory updates to critical exploits. You usually have to try fairly hard not to get the update once Yahoo! has issued one.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Yahoo! Protocol: Part 11 - Booters Introduction(4)
  2. Yahoo! Protocol: Part 18 - Arbitrary Code Execution(0)
  3. Yahoo! Protocol: Part 19 - Conclusion(0)
  4. Unable To Log Into Yahoo! Chat?(3)
  5. New Yahoo! Web Messenger(12)
  6. Yahoo Mail Going Unlimited(24)
  7. The State Of Yahoo! Chats(1)
  8. Yahoo Mail With Yahoo Chat(7)
  9. How To Watch Videos On Yahoo?(2)
  10. I Would Hope Yahoo! Would Get A Clue(0)
  11. Two For The Price Of One: New Messenger Exploit And A New Way To Get It(7)
  12. Yahoo! Chat Room Survey(1)
  13. The Yahoo! Messenger Zero-day For The Month Of August(1)
  14. Captchas + Yahoo! Chat = No Bots (for Now)(14)
  15. “discovr” New Friend With Yahoo! Messenger(2)
  1. Messenger Mail Bug?(2)
  2. Minor Updates To Yahoo! Messenger Web(1)
  3. Yahoo! Messenger Author’s New Security Book(0)
  4. Yahoo! Messenger 9 Beta Preliminary Review(13)
  5. Tapping Yahoo! Messenger Phone Conversations(4)
  6. Hacking Yahoo! Messenger(12)
  7. Yahoo! May Add Openid Support(1)
  8. Optimize Your Site For Yahoo(1)
  9. Who Uses A Yahoo E-mail(8)
  10. It Still Looks Like Microsoft Messenger May Still Happen(9)
  11. Yahoo! Dodges The Bullet(4)
  12. Yahoo! Messenger Talking To Google Talk?(7)
  13. Get Paid To Search Yahoo!(10)


 



- Lo-Fi Version Time is now: 9th July 2008 - 04:36 AM