ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

AIM users prone to name hijacks

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 01 Dec 2000 10:32 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users of America Online's Instant Messenger application are in danger of losing their on-screen identities.

On Wednesday, two AOL user sites -- Inside-AOL.com and AOL-Files.com -- revealed that the accounts of AIM users were being stolen by hackers using a technique that has been wafting about the Internet for weeks.

"This vulnerability was known to AOL for a significant amount of time before we released it," the two sites said in a combined statement released Wednesday. "It was known to a large underground user base of AIM aficionados... and can be utilised without significant expertise in or knowledge of AOL."

Adrian Lamo, the founder and a staff writer for Inside-AOL, accused the Internet giant of not closing the hole in a timely manner.

"AOL isn't really paying attention to policy flaws and security flaws, and by bringing attention to it a public forum, we hope to get AOL to fix the problem," Lamo said.

The flaw has been used for more than a month by hackers to compromise AIM accounts, but the hijacking has picked up significantly in the past few weeks.

AOL could not be reached for comment prior to publication of this article.

Using an internal AOL administration tool readily available on the Internet, name hijackers can send a specific set of commands to the AIM registration server, instructing it to grant a name that already exists. The technique exploits a flaw in the AIM servers that allows a vandal to steal a user's account only if a name consisting of all but the first two letters of the user's account has not been registered. For example, if a hacker wanted to steal the account of "Joe User," he could steal it by registering "e User" with the AIM server.

Using an administration tool, the hacker can add the first two letters to the name.

Until AOL fixes the server, users can protect themselves by registering the name that hackers use (the name minus the first two letters). To do so, follow these steps:

1) Go to this AOL IM registration page. 2) Register your name minus the first two letters. If you are EXAMPLENAME, then register AMPLENAME.

If the registration process says that the "nick" was taken, then it's likely that the name has been legitimately registered. If it allows the name to be registered, then it means that the original name is protected against hijacking.

The flaw only makes stand-alone AIM users vulnerable. Members of America Online -- that is, people who use AOL for Internet access -- don't have to worry, according to Inside-AOL.com.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
63 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Support Analyst

Account management creation, administration and disabling of user accounts for trial and live purposes. Support Analyst Reading, Berkshire Salary: ...

Support Analyst - System Administration

Position: Support Analyst - System Administration Reference: BOA2737 Location: Croydon Salary: Competitive + excellent benefits The role: Bank of ...

Security Document Manager

Ensure that secure assets are not held by projects, programmes and accounts when this is not necessary. Administration of a Battlespace Secure item ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment