Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
2 users currently in General Chat: Ailure, Dark Vampriel | 1 guest
Acmlm's Board - I2 Archive - General Chat - MSN Messenger Exploit Goes Public | |
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 2154/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 02-12-05 01:38 AM Link | Quote
For those who use MSN Messenger, probably now is a good time to use another client for the time being or get a patch (if it has been released)

MSN Messenger Exploit Code Goes Public

Interestingly, the exploit is PNG related, so it seems that JPG is not the only format with embedded executable code...
DarkSlaya
POOOOOOOOOOOORN!
Level: 88

Posts: 3438/4249
EXP: 6409254
For next: 241410

Since: 05-16-04
From: Montreal, Quebec, Canada

Since last post: 8 hours
Last activity: 5 hours
Posted on 02-12-05 01:48 AM Link | Quote
Only affect 6.1 and 6.2

Also doesn't affect WinXP either, according to Microsoft.
dan

Snap Dragon
Level: 43

Posts: 421/782
EXP: 534516
For next: 30530

Since: 03-15-04

Since last post: 20 hours
Last activity: 14 hours
Posted on 02-12-05 02:07 AM Link | Quote
Apparently the exploit is in the library that Microsoft used to implement PNG support in their application. And the vulnerability has been known about since last August (and it was patched then) or something. It's yet another case of Microsoft being lazy with security holes.
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 3194/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 02-12-05 03:02 AM Link | Quote
I'd try to count how many buffer overflows there have been in M$ products, but I'd end up with one. But libpng? I think a lot of programs use that...
Nebetsu

Shmee
Level: 55

Posts: 1004/1574
EXP: 1291130
For next: 23059

Since: 09-01-04
From: Nebland

Since last post: 3 hours
Last activity: 1 hour
Posted on 02-12-05 04:06 AM Link | Quote
I'm using Ayttm at the moment and it doesnt support avatars! I'm safe.
Kitten Yiffer

Purple wand
Furry moderator
Vivent l'exp����¯�¿�½������©rience de signalisation d'amusement, ou bien !
Level: 135

Posts: 7823/11162
EXP: 28824106
For next: 510899

Since: 03-15-04
From: Sweden

Since last post: 3 hours
Last activity: 4 min.
Posted on 02-12-05 04:19 AM Link | Quote
Originally posted by DarkSlaya
Also doesn't affect WinXP either, according to Microsoft.
And that means that I will be pretty much safe anyway.

Althought, this beats the safety issue with MIDI files and Direct-x. By far.
FreeDOS

Lava Lotus
Wannabe-Mod :<
Level: 59

Posts: 1101/1657
EXP: 1648646
For next: 24482

Since: 03-15-04
From: Seattle

Since last post: 6 hours
Last activity: 4 hours
Posted on 02-12-05 10:42 AM Link | Quote
the libpng homepage lightens up with more info. But I'm just surprised that Microsoft uses it. Much more importantly, why don't they use it in IE?
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 2160/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 02-12-05 11:18 AM Link | Quote
it they are devoting their time more to other internet technologies such as intelligent search and what not... the question of when IE7 comes out is answered the same way as for Duke Nukem Forever
FreeDOS

Lava Lotus
Wannabe-Mod :<
Level: 59

Posts: 1103/1657
EXP: 1648646
For next: 24482

Since: 03-15-04
From: Seattle

Since last post: 6 hours
Last activity: 4 hours
Posted on 02-12-05 12:07 PM Link | Quote
You wanted IE7? Ok, it's not Internet Explorer 7.0. That's probably coming in never.
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 2164/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 02-12-05 12:17 PM Link | Quote
hmm...so, it seems people are taking Internet Explorer into their own hands. That makes me wonder, is there anyone out there who will defend Microsoft? (Someone not officially with the company)


(edited by neotransotaku on 02-12-05 08:17 AM)
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1351/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 02-12-05 12:26 PM Link | Quote
Wow, a day where there's an exploit discovered in a Microsoft product. That must mean today's one of those days that ends in a "y".



Oh well, I don't use the official MSN clients.

But yeah, exploits for MS stuff are found very, very, very frequently....
Surlent
サーレント
Level: 49

Posts: 763/1077
EXP: 863920
For next: 19963

Since: 03-15-04
From: Tower of Lezard Valeth

Since last post: 16 hours
Last activity: 1 hour
Posted on 02-12-05 01:22 PM Link | Quote
PNG is my favourite format, unless I want to create animated images (MNG still is very unknown) or want to show large image files like desktop wallpapers, this done with JPG.
Although I'm using Miranda IM, I hope that program is somehow safe; it uses its own MSN protocol, but on the other hand these exploits are also affecting other applications, like HH said

Whatever, even without these security issues, MSN is a way-overcrowded messenger for me. Easy camera and voice support might be good, but hence a naked Miranda IM like Firefox:

In the first start up it is "naked", but once you install the plugins (extensions for Firefox), you'll be able to customize it in your needs. No crappy buggy MSN errors, far less RAM usage and started up in less than two seconds
</advertisement mode>
Kitten Yiffer

Purple wand
Furry moderator
Vivent l'exp����¯�¿�½������©rience de signalisation d'amusement, ou bien !
Level: 135

Posts: 7841/11162
EXP: 28824106
For next: 510899

Since: 03-15-04
From: Sweden

Since last post: 3 hours
Last activity: 4 min.
Posted on 02-12-05 03:11 PM Link | Quote
Originally posted by Tarale
But yeah, exploits for MS stuff are found very, very, very frequently....
Then, MS products are used very frequently too.

IE7 isn't coming in awhile, I would be surprised if it came with Longhorn but... that's the only possible anyway.
dan

Snap Dragon
Level: 43

Posts: 422/782
EXP: 534516
For next: 30530

Since: 03-15-04

Since last post: 20 hours
Last activity: 14 hours
Posted on 02-12-05 05:39 PM Link | Quote
Originally posted by Surlent
PNG is my favourite format, unless I want to create animated images (MNG still is very unknown) or want to show large image files like desktop wallpapers, this done with JPG.
Although I'm using Miranda IM, I hope that program is somehow safe; it uses its own MSN protocol, but on the other hand these exploits are also affecting other applications, like HH said


Yes, it has affected other programs, but the vulnerability has been known about since the middle of last year. Most applications that use libpng have patched the vulnerability, so it's likely that Miranda doesn't have the exploit any more. (If it did at all)
Ran-chan

Moldorm
eek, when are they going to stop growing...
Level: 143

Posts: 7498/12781
EXP: 35293588
For next: 538220

Since: 03-15-04
From: Nerima District, Tokyo - Japan

Since last post: 12 hours
Last activity: 12 hours
Posted on 02-12-05 07:16 PM Link | Quote
If Windows XP can
Rox 4 Ever

Red Goomba
Level: 12

Posts: 28/47
EXP: 7635
For next: 286

Since: 04-20-04
From: Mirabel,Quebec,Canada.

Since last post: 120 days
Last activity: 2 days
Posted on 02-12-05 11:53 PM Link | Quote
Me,i have msn messenger v 6.2 and it dosent work.I dont know why but it make me angry.
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 2169/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 02-13-05 12:52 AM Link | Quote
Originally posted by Trapster
I like the JPG format.


Wait until I send you a JPG that has my own virus. I want to see your virus scanner block that

Anyways, my friend tried to use his MSN Messenger yesterday and the system wouldn't let him log in until he updated (or used another client )
Ran-chan

Moldorm
eek, when are they going to stop growing...
Level: 143

Posts: 7508/12781
EXP: 35293588
For next: 538220

Since: 03-15-04
From: Nerima District, Tokyo - Japan

Since last post: 12 hours
Last activity: 12 hours
Posted on 02-13-05 01:47 AM Link | Quote
Maybe it can
neotransotaku

Baby Mario
戻れたら、
誰も気が付く
Level: 87

Posts: 2176/4016
EXP: 6220548
For next: 172226

Since: 03-15-04
From: Outside of Time/Space

Since last post: 11 hours
Last activity: 1 hour
Posted on 02-13-05 03:41 AM Link | Quote
well, if it is brand new virus, how will it find it
FreeDOS

Lava Lotus
Wannabe-Mod :<
Level: 59

Posts: 1108/1657
EXP: 1648646
For next: 24482

Since: 03-15-04
From: Seattle

Since last post: 6 hours
Last activity: 4 hours
Posted on 02-13-05 04:11 PM Link | Quote
Originally posted by Kitten Yiffer
Originally posted by Tarale
But yeah, exploits for MS stuff are found very, very, very frequently....
Then, MS products are used very frequently too.


It's been proven that most of the time, Microsoft products are just insecure in nature. The popularity has little effect. Go look it up.
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - General Chat - MSN Messenger Exploit Goes Public | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.016 seconds.