Forums: Yahoo Filename Exploit - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Yahoo Filename Exploit Any more info or links to info?

#1 User is offline   Nick W 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,250
  • Joined: 12-August 03

Posted 08 January 2004 - 12:05 PM

This is not a link on ComSec's current Secunia weekly mailing. It just came out today and is pretty big, IMHO.

http://www.secunia.c...visories/10573/

Does anyone have any links to furthur info regarding this? Of particular interest is the part where it says users won't be able to update to patch. I find that very interesting.
0

#2 Guest_chaat_sleuth_*

  • Group: Guests

Posted 08 January 2004 - 01:41 PM

to my knowledge there never has been a manual update function available in yahoo messenger, it auto updates within a few days after a new version is released......this vulnerability has been reported in 1351 and prior.. but most users already have 1356 because of the auto update.

further more when you go to messenger.yahoo.com it WILL update to 1358 if you are running a prior version without uninstalling.
oh and by the way yahoo never releases any info about what they fixed or not in any of their new versions. :unsure:





-- dethink to survive --
0

#3 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,447
  • Joined: 18-August 06

Posted 08 January 2004 - 03:49 PM

yup details as follows


Quote

Date:  Thu, 8 Jan 2004 03:38:43 -0800
From:  Tri Huynh <trihuynh@zeeup.com>
Subject:  Yahoo Instant Messenger Long Filename Downloading Buffer Overflow


Yahoo Instant Messenger Long Filename Downloading Buffer Overflow
  =================================================

  PROGRAM: Yahoo Instant Messenger (YIM)
  HOMEPAGE: http://messenger.yahoo.com
  VULNERABLE VERSIONS: 5.6.0.1351 and below


  DESCRIPTION
  =================================================

  YIM is one of the most popular instant messengers. This is a cool product
that supports many  useful features like audio/video chatting, file
transferring...

Fore more details about the product, please go to http://messenger.yahoo.com

  DETAILS
  =================================================

By sending a specially crafted long filename to a user, an attacker can
cause a buffer overflow when the user's YIM tries to download the file
from the server. (No need to run the file).

For a fast demonstration, you can create a file like this
  "test<insert around 210 spaces here>.jpg" and send it to
another user and ask her to download it.

Because this is a buffer overflow, there is always a possibility to
run malicious code on the user's machine.

NOTE : This vulnerability is different from the one was discovered by
Hat-Squad team in October.


  WORKAROUND
  =================================================

Yahoo has been contacted at security@yahoo-inc.com and I got no response
except that they said the are looking to it...and here is the interesting
story on how
Yahoo handle it (after my little investigation) which I quote from an email
I sent
  to a friend in the PenetrationGroup about the issue (sorry for my laziness
8-)  :

"I already contacted Yahoo couple days ago...
.......After reading your email, I removed my YIM and downloaded the new one
from their
website and you are right; the newest version 5.6.0.1358 is not vulnerable.
However,
there is NO WAY to upgrade from 5.6.0.xxxx to 5.6.0.1358 except you
reinstall
YIM; and of course Yahoo doesn't tell anybody about it either.

If you go to http://messenger.yah...enger/security/ you will see
there is
no update for this vulnerability. Again, the only way to patch it is
reinstall YIM
which Yahoo doesn't say anything about it.
(FYI, This vulnerability lays in the file ft.dll which is used to hande file
transferring in YIM.
They do patch this file in the new version, however if you want to dig more
into this thing, you can always get the old file from any of the YIM users
you know easily since nobody reinstall their YIM for no reason.)

So here is the new Yahoo! security strategy. Instead of informing the users
and
issueing a patch, they slip the patch into their main program silently and
say nothing about the vulnerability.  Doing so, they can avoid
  the press to embarass them for leaving so many vulnerabilities in their
product. However,
it is also a big embarassment if they protect ONLY new users who download
the new version and leave millions of other users who are using the old
version with
no patches available and are uninformed of the vulnerability. Yahoo !.....


The only way to patch it is removing and reinstalling YIM from Yahoo
website. Don't
waste your time to look for a patch in the messenger security page or any
info about this vulnerability
from them.  They don't give a damn !

  CREDITS
  =================================================

  Discovered by Tri Huynh from SentryUnion


  DISLAIMER
  =================================================

  The information within this paper may change without notice. Use of
  this information constitutes acceptance for use in an AS IS condition.
  There are NO warranties with regard to this information. In no event
  shall the author be liable for any damages whatsoever arising out of
  or in connection with the use or spread of this information. Any use
  of this information is at the user's own risk.


  FEEDBACK
  =================================================

  Please send suggestions, updates, and comments to: trihuynh@zeeup.com

Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

#4 Guest_oxydrine_*

  • Group: Guests

Posted 08 January 2004 - 05:07 PM

Is anybody have this exploit or seen it or test it ?
0

#5 User is offline   Train25 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 82
  • Joined: 30-November 03

Posted 08 January 2004 - 05:33 PM

Quote

For a fast demonstration, you can create a file like this
  "test<insert around 210 spaces here>.jpg" and send it to
another user and ask her to download it.


There is your answer. Embed in the image file with a self installing exe and you are all set
0

#6 User is offline   alibaba 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 81
  • Joined: 04-December 03

Posted 09 January 2004 - 12:14 AM

but I have heard that you cant embed an executable in a jpeg.Even if you can ,It wont execute because the file extention has to be .exe
0

#7 User is offline   Black_hat 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 85
  • Joined: 23-July 03

Posted 10 January 2004 - 09:26 AM

This prolbem Filtered by Yahoo servers .... you can not upload the file with long file name to victim . You can test it :(
:ph34r:
Black_Hat
0

#8 User is offline   Nick W 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,250
  • Joined: 12-August 03

Posted 11 January 2004 - 10:07 PM

Thanks Comsec. Looks like they are filtering this one though, or something.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting