Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Yahoo! Protocol: Part 19 - Conclusion
tansqrx
post Apr 29 2007, 05:41 AM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 533
Joined: 25-April 05
Member No.: 4,374



Throughout this tutorial the main objectives has been covered. Part 12 describes the exact packet structure generated by the shared files boot. Part 15 shows that it is possible to write a booter from the ground up only using information gathered through a network sniffer. Parts 16-18 shows that a booter performs its work by creating a timing fault that in turn cases the stack to be corrupted and an access violation generated. Part 18 also explores why injection of arbitrary code is not possible using current booter technology.

In my closing opinion, I believe that Yahoo! has dodged the bullet for this exploit. This particular exploit has been in existence since mid-2004, and even with auto updates, Yahoo! has failed to fix this problem. If the stack corruption had occurred in any other place it may have been possible to run arbitrary code and a much more serious situation would occur. Program bug removal has always been a large problem for coders, especially with such a large user base as Yahoo! Messenger. There are hundreds if not thousands of rogue users all working against Yahoo! Messenger and the YMSG protocol. The question is not if another booter will expose itself but when. When the next round of booters are released, will random luck cause the program to crash in the program execution path or will it open a new door to run injected code? Only time will tell.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Yahoo! Messenger Protocol Tutorial - Part 2(2)
  2. Yahoo! Protocol: Part 11 - Booters Introduction(4)
  3. Unable To Log Into Yahoo! Chat?(3)
  4. New Yahoo! Web Messenger(12)
  5. Yahoo Mail Going Unlimited(24)
  6. The State Of Yahoo! Chats(1)
  7. Yahoo Mail With Yahoo Chat(7)
  8. How To Watch Videos On Yahoo?(2)
  9. I Would Hope Yahoo! Would Get A Clue(0)
  10. Yahoo! Chat Room Survey(1)
  11. The Yahoo! Messenger Zero-day For The Month Of August(1)
  12. Captchas + Yahoo! Chat = No Bots (for Now)(15)
  13. “discovr” New Friend With Yahoo! Messenger(2)
  14. Minor Updates To Yahoo! Messenger Web(1)
  15. Yahoo! Messenger Author’s New Security Book(0)
  1. Yahoo! Messenger 9 Beta Preliminary Review(13)
  2. Tapping Yahoo! Messenger Phone Conversations(4)
  3. Hacking Yahoo! Messenger(12)
  4. Yahoo! May Add Openid Support(1)
  5. Optimize Your Site For Yahoo(1)
  6. Latest Yahoo! Vulnerability Appears To Be A Moving Target For Messenger(2)
  7. Who Uses A Yahoo E-mail(8)
  8. Yahoo! Dodges The Bullet(4)
  9. Yahoo! Messenger Talking To Google Talk?(7)
  10. Get Paid To Search Yahoo!(10)
  11. Yahoo! Search Boss(5)
  12. Yahoo! Messenger Power User(1)
  13. Yahoo! Messenger Challenge Response Algorithm(11)


 



- Lo-Fi Version Time is now: 13th October 2008 - 04:27 AM