Go Back   Novahq.net Forum > Off-Topic > General Chat
FAQ Community Calendar Today's Posts Search

General Chat Talk about anything that does not fit into other topics here.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 02-11-2005, 03:28 PM
zaitsev is offline zaitsev
Registered User

Join Date: Jan 2004
Posts: 217

Post MSN Messenger Security Flaw

MSN Security Flaw

Quote:
BOSTON, MA: FEBRUARY 8, 2005 – Core Security Technologies, provider of CORE IMPACT, the first-to-market penetration testing product for assessing specific information security risks, today published a vulnerability in Microsoft’s MSN Messenger, an instant messaging program currently used by over 130 million people worldwide. Core researchers discovered that by selecting a specially-crafted graphic as the user’s display picture in MSN Messenger, an attacker could trigger a buffer overflow vulnerability on the chat partner’s computer and surreptitiously take over machines running instant messaging software. The attack would travel through the established chat session and would pass unnoticed by firewalls, network intrusion detection systems and even host-based personal firewalls and antivirus software. According to the vendor, Windows Messenger and Windows Media Player are also affected by this vulnerability.
“This is a critical security flaw since it directly affects more than 130 million users and because the attack is very likely to go unnoticed by the several layers of security countermeasures commonly used today,” said Ivan Arce, CTO at Core Security Technologies. “Since initially reporting the flaw, we have been working closely with the vendor and we are pleased to see that a fix is now available.”

Vulnerability Specifics: The MSN Messenger protocol allows for the transmission of images between users during electronic conversations. The image format used to transfer those images is called Proprietary Network Graphics (PNG). When a user selects a picture to be displayed, Messenger converts it to the PNG format, with a fixed size and encoding characteristics. These images are then transmitted over the same communication channel used to exchange text messages. By sending a specially crafted PNG image, an attacker can trigger a buffer overflow and execute arbitrary code on the chat partner’s machine.

Other Vulnerability Related Facts:

Microsoft estimates the number of MSN Messenger users to be around 130 million worldwide (http://www.microsoft.com/presspass/p...FlirtingPR.asp).
Systems running vulnerable MSN Messenger clients on Windows XP with Service Pack 2 installed are also exploitable.
The vulnerability is exploitable in MSN Messenger client software up to version 6 including binary files compiled with the Visual Studio GS stack overflow protection mechanism. MSN Messenger 7 (beta) clients are not vulnerable.
Exploitation of the vulnerability can be carried out though the same communications channel used by legitimate users for normal chat sessions, therefore it is very difficult to differentiate attacks from normal traffic.
A similar vulnerability in the open source libPNG image-processing library was discovered by Chris Evans and fixed in August 2004.

Microsoft denies this security flaw has anything to do with the MSNM network being down.
Reply With Quote
  #2  
Old 02-12-2005, 04:32 AM
BADDOG is offline BADDOG
resigned

Join Date: Mar 2002
Posts: 7,050

Confused

Nothing surprises me when it comes to Microsoft products bro!

Regards
Reply With Quote
  #3  
Old 02-12-2005, 10:41 AM
Hellfighter is offline Hellfighter
Hellfighter's Avatar
Chief ADFP

Join Date: Jun 2002
Location: San Jose Calif 95111
Posts: 21,143

Send a message via ICQ to Hellfighter
will all one has to do not to take trasfer images of any type at all using the messager other wise that is only weak point it has the beta messager is cover for no weak point. so it is in the works and they know of it. i did a update with windows update site they had a new patch out dated feb/10/2005 don't know if it cover it or not did not read into it.
__________________
* altnews sources [getmo & others news] not found main FNN: realrawnews.com
*Discord: Unknown77#7121
Playing now days: EA Games> swtor [star wars old republic]
Reply With Quote
  #4  
Old 02-13-2005, 02:47 AM
Spongebob123 is offline Spongebob123
Registered User

Join Date: Feb 2005
Posts: 7

is MSN a news channel?
Reply With Quote
  #5  
Old 02-13-2005, 03:19 AM
Hellfighter is offline Hellfighter
Hellfighter's Avatar
Chief ADFP

Join Date: Jun 2002
Location: San Jose Calif 95111
Posts: 21,143

Send a message via ICQ to Hellfighter
its a MicroSoft Network they all so give internet services too
__________________
* altnews sources [getmo & others news] not found main FNN: realrawnews.com
*Discord: Unknown77#7121
Playing now days: EA Games> swtor [star wars old republic]
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
MSN Live Messenger web-cam Hellfighter Humor & Jokes 3 07-02-2006 12:26 AM
Msn Messenger 8.0 J-Factor Hardware and Software 4 06-30-2006 05:56 PM
MSN Messenger Chrispy General Chat 10 12-04-2005 10:18 AM
Worm Chatter Escalates on MSN Messenger DevilDog#1 Hardware and Software 1 03-08-2005 01:41 PM
Security flaw disclosed in Windows DevilDog#1 General Chat 0 11-21-2002 11:07 PM


All times are GMT -5. The time now is 02:22 PM.




Powered by vBulletin®