Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 26th, 2002, 02:14 PM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,129
Default Security problems in Yahoo Messenger

SecurityFocus reports at http://online.securityfocus.com/archive/1/257584
a series of security
problems affecting the correct functioning of Yahoo Messenger version 5.

This version of Yahoo Messenger listens on port 5101 of the client computer,
which creates a series of problems that could be exploited by an attacker
that sends traffic to the aforementioned port in the targeted user's
computer. More precisely, an attacker could perform the following actions on
the affected system:

-Carry out a denial of service attack on Yahoo Messenger by overflowing the
message field in the yahoo protocol. Similar effects can be caused by
overflowing the Imvironment field.

-Send messages under another name, impersonating a sender.

-Send multiple messages from different names, flooding a certain user with
messages and overloading their client.

-Add a person to their list of contacts *(without the person's consent) and
send messages to them until the person's IP address is sent in a message
over Yahoo's server.
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:40 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums