Programming C, C++, Java, PHP, Ruby, Turing, VB
Computer Science Canada 
Programming C, C++, Java, PHP, Ruby, Turing, VB  

Username:   Password: 
 RegisterRegister   
 Display Picture vulnerability discovered in MSN Messenger 6
Index -> General Discussion
View previous topic Printable versionDownload TopicSubscribe to this topicPrivate MessagesRefresh page View next topic
Author Message
Amailer




PostPosted: Tue Feb 08, 2005 3:29 pm   Post subject: Display Picture vulnerability discovered in MSN Messenger 6

http://mess.be/ wrote:
We have obtained new details on the previously announced Microsoft Security Bulletins. Core Security Technologies today published a vulnerability in MSN Messenger clients up to version 6. According to the report, using a specially-crafted MSN Display Picture, an attacker could trigger a buffer overflow vulnerability on a contact's computer and execute arbitrary code.

The attack would travel through the established chat session and would pass unnoticed by firewalls, network intrusion detection systems and even host-based personal firewalls and antivirus software. Windows Messenger and Windows Media Player are also affected by this vulnerability.

"This is a critical security flaw since it directly affects more than 130 million users and because the attack is very likely to go unnoticed by the several layers of security countermeasures commonly used today," said Ivan Arce, CTO at Core Security Technologies. "Since initially reporting the flaw, we have been working closely with [Microsoft] and we are pleased to see that a fix is now available."

NOTE: MSN Messenger 7 BETA is NOT vulnerable. Download it here.

>> Join the February Security Bulletins webast for a brief overview of the technical details followed by an extensive Q&A session. Tomorrow at this time and recommended to IT professionals only.


Yeah so this could be the reason why msn is down for many people.
Also you will be asked to do 9 updates by windows updater XD
Sponsor
Sponsor
Sponsor
sponsor
Tony




PostPosted: Tue Feb 08, 2005 3:50 pm   Post subject: (No subject)

it's a scam to get people to start using MSN 7 Confused

anyways - wouldn't the user first have to add the attacker to their contact list for the vulnerability to open up? Thinking
Amailer




PostPosted: Tue Feb 08, 2005 4:15 pm   Post subject: (No subject)

Well it can travel through conversations so if someone added the attacker and that someone is somehow connected to you by someone elses... list.. yeah you'll get it. Anyhow.. is it just me or is msn.com and http://www.imagine-msn.com/messenger/ and etc screwed up? (links-- errors)
Tony




PostPosted: Tue Feb 08, 2005 4:23 pm   Post subject: (No subject)

msn.com is noticably slow
messanger times out (well... my patience timed out and I closed the window)

as for the MSN's DP vulnerability -- I thought the person had to be on your list for DB to be displayed. Though I suppose it could be forced from the other side.. Thinking
md




PostPosted: Tue Feb 08, 2005 4:26 pm   Post subject: (No subject)

I think something else is affecting MSN, acuse DPs wouldn't affect the servers...
Tony




PostPosted: Tue Feb 08, 2005 5:13 pm   Post subject: (No subject)

well there's that Bropia.F/Agabot.ajc worms (link) from few days ago. I'm suspecting that they forced the network down. Seems that webserver side of MSN division is affected as well.
MihaiG




PostPosted: Tue Feb 08, 2005 6:49 pm   Post subject: (No subject)

is that how you got in my comp tony? adn martin grrr Twisted Evil Twisted Evil Twisted Evil
Martin




PostPosted: Tue Feb 08, 2005 6:52 pm   Post subject: (No subject)

Come now, that would be amateur.
Sponsor
Sponsor
Sponsor
sponsor
Amailer




PostPosted: Tue Feb 08, 2005 6:53 pm   Post subject: (No subject)

martin wrote:
Come now, that would be amateur.

LOL I think its time for the release! Come on!
Dan




PostPosted: Wed Feb 09, 2005 10:13 am   Post subject: (No subject)

Pff, i have been telling peoleop the DP in msn have been wrong since the day they came out.......that cases many problems and secuity realted issues. hostly i think msn whould probly be better off w/o them, but i run linux so i am safe from this crazyness =p
Computer Science Canada Help with programming in C, C++, Java, PHP, Ruby, Turing, VB and more!
Tony




PostPosted: Wed Feb 09, 2005 11:12 am   Post subject: (No subject)

Hacker Dan wrote:
but i run linux so i am safe from this crazyness


me too - my computer won't boot up Laughing
Martin




PostPosted: Wed Feb 09, 2005 11:54 am   Post subject: (No subject)

Amailer wrote:
martin wrote:
Come now, that would be amateur.

LOL I think its time for the release! Come on!

Shhh!

Not yet.
Drakain Zeil




PostPosted: Sat Feb 12, 2005 9:44 am   Post subject: (No subject)

Ugh, the new WINKS!!! junk can only bring nothing good to the world...

Install Linux, get KDE running, run Kopete. Problem solved.
Display posts from previous:   
   Index -> General Discussion
View previous topic Tell A FriendPrintable versionDownload TopicSubscribe to this topicPrivate MessagesRefresh page View next topic

Page 1 of 1  [ 13 Posts ]
Jump to:   


Style:  
Search: