Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> The Yahoo! Messenger Zero-day For The Month Of August
tansqrx
post Aug 16 2007, 08:59 PM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 521
Joined: 25-April 05
Member No.: 4,374



Yahoo! Messenger is once again in the news for all the wrong reasons. This time it is a heap overflow in the webcam component. The news was apparently first exposed my McAfee in a blog post at http://www.avertlabs.com/research/blog/ind...enger-zero-day/. A second post at http://www.avertlabs.com/research/blog/ind...er-webcam-0day/ goes into more detail explaining that you shouldn’t accept unknown webcam invites and to possibly firewall port 5100. Security Focus has also issued an alert at http://www.securityfocus.com/bid/25330/info but they only classify is as a remote denial of service attack, far from the remote code execution heralded by McAfee. Security Focus reports that exploit code can be found at http://www.team509.com/expyahoo.rar.

When I hear that a new exploit may be on the market for Messenger the first thing I do is head over to Google News and see what the top Messenger stories are. For some reason I think this particular exploit may be getting the attention of a more generalized audience. Compared to the June 2007 exploit, the news reports appear to be more numerous and written in a more ominous tone. The thing that really caught my attention was the fact that more main stream media outlets are picking up on this story such as ABC (http://www.abcnews.go.com/Technology/PCWorld/story?id=3482490). Although this particular Yahoo! Messenger attack may not be any worse than the June exploit, Yahoo! may have a bigger public relations mess on their hands.
Go to the top of the page
 
+Quote Post
tansqrx
post Aug 23 2007, 08:48 PM
Post #2


Super Member
Group Icon

Group: [HOSTED]
Posts: 521
Joined: 25-April 05
Member No.: 4,374



Security Fix 8.1.0.416

On the 16th of August I reported the latest Yahoo! Messenger exploit that was leaked. At the time not much information was given about the exploit but since then I have a little bit more. The exploit was apparently due to a buffer overflow in the JPEG2000 (http://en.wikipedia.org/wiki/JPEG_2000) CODEC.

Yahoo! has now announced that the exploit has been patched in its latest release, 8.1.0.416. The patch should be automatically pushed out to users.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Yahoo! Messenger Protocol Tutorial - Part 2(2)
  2. Yahoo! Protocol: Part 11 - Booters Introduction(4)
  3. Unable To Log Into Yahoo! Chat?(3)
  4. Yahoo Mail Going Unlimited(24)
  5. The State Of Yahoo! Chats(1)
  6. Yahoo Mail With Yahoo Chat(7)
  7. How To Watch Videos On Yahoo?(2)
  8. I Would Hope Yahoo! Would Get A Clue(0)
  9. Two For The Price Of One: New Messenger Exploit And A New Way To Get It(7)
  10. Yahoo! Chat Room Survey(1)
  11. Captchas + Yahoo! Chat = No Bots (for Now)(15)
  12. “discovr” New Friend With Yahoo! Messenger(2)
  13. Messenger Mail Bug?(2)
  14. Minor Updates To Yahoo! Messenger Web(1)
  15. Yahoo! Messenger Author’s New Security Book(0)
  1. Yahoo! Messenger 9 Beta Preliminary Review(13)
  2. Tapping Yahoo! Messenger Phone Conversations(4)
  3. Hacking Yahoo! Messenger(12)
  4. Yahoo! May Add Openid Support(1)
  5. Optimize Your Site For Yahoo(1)
  6. Latest Yahoo! Vulnerability Appears To Be A Moving Target For Messenger(2)
  7. Who Uses A Yahoo E-mail(8)
  8. It Still Looks Like Microsoft Messenger May Still Happen(9)
  9. Yahoo! Dodges The Bullet(4)
  10. Yahoo! Messenger Talking To Google Talk?(7)
  11. Get Paid To Search Yahoo!(10)
  12. Yahoo! Search Boss(5)
  13. Yahoo! Messenger Power User(1)


 



- Lo-Fi Version Time is now: 29th August 2008 - 07:16 AM