Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
0 user currently in Hardware/Software.
Acmlm's Board - I2 Archive - Hardware/Software - SECURITY HOLE: AOL Instant Messenger | |
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 259/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 08-11-04 10:47 AM Link | Quote
FYI, there is a "critical security hole" in AOL Instant Messenger. Seeing as so many people here are AIM users, I thought I would pass this on so that you know.

There is an news article here: AOL IM "Away" message flaw deemed critical
and a more specific outline of the problem here: iDEFENSE:

I'm sure most of you use an alternate IM client (ie, Trillian, gAIM, Adium, etc) but for those who are using AOL's AIM client, this is for you. You guys will have to either switch to a different AIM client, or upgrade to the most recent beta available from the AIM site.

Enjoy.
FreeDOS

Lava Lotus
Wannabe-Mod :<
Level: 59

Posts: 624/1657
EXP: 1648646
For next: 24482

Since: 03-15-04
From: Seattle

Since last post: 6 hours
Last activity: 4 hours
Posted on 08-11-04 01:34 PM Link | Quote
Real news would be a version of AIM without exploits.
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 261/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 08-11-04 01:52 PM Link | Quote
True, but they don't usually announce the danged things a whole lot. Still, thought it would be fair to warn those that are using AIM. Which incidentally, is not me.
Kitten Yiffer

Purple wand
Furry moderator
Vivent l'exp����¯�¿�½������©rience de signalisation d'amusement, ou bien !
Level: 135

Posts: 4056/11162
EXP: 28824106
For next: 510899

Since: 03-15-04
From: Sweden

Since last post: 3 hours
Last activity: 4 min.
Posted on 08-11-04 03:03 PM Link | Quote
AOL should make AIM from scratch. You know it's outdated when the folder it's installed in is called AIM95...

I have used Trillian since long time ago. I still use the MSN client seperatly, but just becuse of some of the features it have (which Trillian dosen't support )

If it's not Trillian I use, it's GAIM.
Surlent
サーレント
Level: 49

Posts: 528/1077
EXP: 863920
For next: 19963

Since: 03-15-04
From: Tower of Lezard Valeth

Since last post: 16 hours
Last activity: 1 hour
Posted on 08-11-04 06:50 PM Link | Quote
Originally posted by Yuri

[...]
If it's not Trillian I use, it's GAIM.

Or just use Miranda IM
It's very small, hardly uses any system resources and unites ICQ, AIM, MSN and an IRC client.
As for AIM, usually I was satisfied with it (unlike the ICQ stand-alone messenger which sometikes takes ages to load at its start-up), but hearing about these security issues is not too good. Even the firewall cannot prevent these issues, since the required port(s) anyway need(s) to be open and any chat application requires server access


(edited by Surlent on 08-11-04 09:51 AM)
DarkSlaya
POOOOOOOOOOOORN!
Level: 88

Posts: 1064/4249
EXP: 6409254
For next: 241410

Since: 05-16-04
From: Montreal, Quebec, Canada

Since last post: 8 hours
Last activity: 5 hours
Posted on 08-11-04 07:11 PM Link | Quote
I used to use AIM but now I use Trillian. I could've been killed if I wouldn't have switched!
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 262/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 08-12-04 04:11 AM Link | Quote
Ah, Surlent, I forgot Miranda, didn't I?

I've used that before too, and I quite like that one as well, and just that little more versatile than Trillian is out-of-the-box too

Course, I don't use Miranda at the moment, I'm using Adium. Fear the duck.
FreeDOS

Lava Lotus
Wannabe-Mod :<
Level: 59

Posts: 626/1657
EXP: 1648646
For next: 24482

Since: 03-15-04
From: Seattle

Since last post: 6 hours
Last activity: 4 hours
Posted on 08-12-04 07:30 AM Link | Quote
Of course, any exploit is serious and shouldn't be ignored...

It's also impossible (almost) to list nearly every AIM clone, or every program that supports AIM . Most probably don't work, some probably haven't gotten past the stage of "Hey, it'll be cool to make my own AIM program!" For myself, I use Gaim, partly because it's more secure than the real AIM, partly because the official AIM client on Linux sucks.
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 1195/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 08-12-04 08:16 AM Link | Quote
hmm....buffer overrun...don't you love these C vulnerabilities

anyways, i'm not sure if I'm going to change over to a different AIM client and I'm relucant to upgrade past AIM v5.2. Not sure what I'm going to do

thanks for the tip off
Shadic

Cukeman
Level: 27

Posts: 60/304
EXP: 111073
For next: 5086

Since: 08-20-04
From: Somewhere, Over the Rainbow!

Since last post: 9 days
Last activity: 2 hours
Posted on 08-28-04 08:29 AM Link | Quote
Wait, you have to click on a link?

If I read that right, it's nothing. >.< Just don't click on hotlinks from people you don't trust.
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 279/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 09-02-04 05:41 PM Link | Quote
It probably is nothing to you, but I wonder how it's going to affect all the users that don't think before they click..
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 1492/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 09-03-04 01:27 AM Link | Quote
It is more serious than it seems. Imagine you had AIM open and came across this in a webpage:
<script>window.open("aim://goaway[exploit code]")</script>
You're screwed.
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 1318/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 09-03-04 04:36 AM Link | Quote
yup...it is pretty much this is why I have now defected from AIM and is now using gaim...
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 698/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 11-03-04 06:58 AM Link | Quote
You know, this can probably be unstickied by now

Unless I find a new vulnerability, of course. Hehehe....


(edited by Tarale on 11-02-04 09:59 PM)
DarkSlaya
POOOOOOOOOOOORN!
Level: 88

Posts: 2415/4249
EXP: 6409254
For next: 241410

Since: 05-16-04
From: Montreal, Quebec, Canada

Since last post: 8 hours
Last activity: 5 hours
Posted on 11-03-04 07:00 AM Link | Quote
Originally posted by Tarale
Unless I find a new vulnerability, of course. Hehehe....


If this is like IE, than you'll find some real fast

But yeah, I guess this Security Hole has been fixed. Hurray for AOHell.
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 1613/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 11-04-04 04:12 AM Link | Quote
this only effected AOL Instant Messenger so I do not think it is so bad since AOLIM is much much better than AOL itself... after all, there is no series of patches that will fix up AOL...
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - Hardware/Software - SECURITY HOLE: AOL Instant Messenger | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.010 seconds.