ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

AIM security hole still threatens users

Published: 07 May 2002 11:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

AOL Time Warner failed to properly fix a security hole in its AOL Instant Messenger application, leaving its users vulnerable to a new way to exploit the same flaw, a security researcher said at the weekend.

The glitch's latest incarnation could have been just as dangerous as the previous version, publicised in January, opening the way for malicious AIM users to execute any program on a vulnerable user's computer, said Matt Conover, a hacker with a security research group known as "w00w00."

"This is almost identical to the problem we found originally, and that's saddening," he said. "By using a slightly different method, we are able to get around the filtering they used to protect against the last flaw."

Last time, the error occurred in how the "add game" command handled a request from another user. This time, it occurs when a malicious AIM user sends an overly long "add external application" command to another user. Known as a buffer overflow, the error allows an attacker to execute a program on the victim's computer.

After being notified by w00w00, AOL Time Warner fixed the problem by again applying a filter to its instant messaging servers, said Conover. Because the fix can be done to AOL's own machines, the protection is immediate, he added.

Attempts to confirm the fix on Sunday with an AOL Time Warner representative were unsuccessful.

Though Conover said AOL responded quickly to the flaw this time, the group still had to use private contacts formed during the last security incident; AOL Time Warner still does not publish a central security contact for its software.

"There is still no way to publicly contact them, which means that they haven't learned anything from the last incident," he said.

Moreover, while AOL Time Warner's fix prevents the current hole from being used to attack another user or to spread worms or viruses through instant message chats, Conover worries that an online vandal may find another method that could also elude AOL's fix.

"I definitely don't think they did enough to secure the IM client," he said. "They responded quickly to this instance of the flaw, but if they stop there, I think they are being lazy."

Because AOL Time Warner fixed only a specific instance of the flaw rather than the network security problems that lead to the vulnerability, the company could see a third strike against its instant messaging client, he said.

"All the code that requests one user to add something from another user needs to be looked at," he said.

The statement echoes another that the w00w00 security team made in its 1 January advisory for the original flaw. "This may be more generic and exploitable through other means, but AOL has not released enough information about their protocol for us to be able to determine that," the group warned.

Conover said that until AOL takes its security to heart, he believes instant messenger users should think about moving to a new software provider.

"We recommend that people use an IM provider that has a means to deal with security issues, because -- right now -- AOL doesn't," he said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
21 out of 61 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains