Home › Forums › Archives › Instant Messaging › Yahoo! Messenger Support › Yahoo exploit- login disconnect
- This topic has 42 replies, 9 voices, and was last updated 18 years, 1 month ago by
khudro.
-
AuthorPosts
-
January 28, 2007 at 2:04 pm #154999
Jeff Hester
KeymasterI found an account locker a while back it locked yahoo accounts for hours, But Yahoo did do something becouse it does not work now.
I only used it for testing. Never against people other then myself or bots.
Torseq tech go here to report your booting info. Report a security vulnerability to Yahoo! – Yahoo! Abuse
January 30, 2007 at 8:29 am #155000Jeff Hester
KeymasterI found an account locker a while back it locked yahoo accounts for hours, But Yahoo did do something becouse it does not work now.
I only used it for testing. Never against people other then myself or bots.
Torseq tech today is the day your going to report what you found on the booter right?
January 31, 2007 at 12:16 am #155019Torseq Tech.
MemberCChris wrote:
Torseq tech today is the day your going to report what you found on the booter right?
I have reported it directly to a Yahoo! admin that I’m working and communicating with. He has directly told me that a fix IS on the way, and knowing this, I will wait a little longer before I disclose this in full (I’ve already partially done so to the public).
You wouldn’t believe how much criticism I’ve received from Yahoo! IM forums around the internet (YMLite forum, the YTK forum and others) for stating that I would go public. Suddenly I’m everybody’s ‘man to hate’. 😀 A threat to take away a child’s toy can really anger some.
January 31, 2007 at 12:23 am #155003Jeff Hester
KeymasterDon’t worry I don’t hate you. I would have posted in on Secunia before I contacted Yahoo. I am so sick of Yahoo sending me stupid replys.
I read your posts and people replying on other forums. I can’t believe how ignorant people are thinking Yahoo will bring you to court. If yahoo would bring anyone to court it would be the person that made the booter.
January 31, 2007 at 12:44 am #155004Jeff Hester
KeymasterDon’t worry I don’t hate you. I would have posted in on Secunia before I contacted Yahoo. I am so sick of Yahoo sending me stupid replys.
I read your posts and people replying on other forums. I can’t believe how ignorant people are thinking Yahoo will bring you to court. If yahoo would bring anyone to court it would be the person that made the booter or the person that has the booter on there website for anyone that wants it.
My favorite post was
Quote:Adam…I hope you have a good team of lawyers waiting. It’s not the smartest thing to threaten a company with possible disruption of service. It’s a little like threatening a company with a virus if they don’t do what you want.The booter is aleady out so how is it a “possible” disruption of service.
January 31, 2007 at 2:05 am #155020Torseq Tech.
MemberI know, Chris, LoL. I already told him my answer to that (whatwasIthinking).
The good news is that the room boot is FINALLY Patched, and what do you know, ON THE 30th DAY of January. =)
January 31, 2007 at 2:11 am #155012Dermot
ParticipantAnd about time too.
January 31, 2007 at 3:17 am #155021Torseq Tech.
MemberThe following is a post made by me regarding Yahoo!’s actual ‘patch’ for this. If you would like to know some of the technical details you can read below. This is also posted on my forum, the YTK board.
Now, for anybody that wants to know the intricate details of this patch, I’ll give you the lowdown…There was a vulnerable field inside of the Chat Message packet (service type: 0x00 0xA8). This field is known as the Message Type Definition field (at least what I call it) as it defines the ‘type’ of ‘message’ for the client to read in. 1,2,3 in ASCII denotes a standard chat message, an emote and lastly a think/thought type of chat message.
What Yahoo! has done with their recent patch (which took place today) is that they are enforcing that this field (124) only contains a single byte of data, thus ‘patching’ the vulnerability that existed. The single byte of data allowed has to be an ASCII numeric value, values 1-6 are allowed. Anything higher than 6 or lower than 1 and your chat message isn’t delivered to the room. Before anybody asks I don’t know why 4-6 are allowed since they’re not used, my guess is that they’re reserved for future use.
On their blog, when I wrote them an open letter about this, I did in fact tell them to enforce a single byte of data (which is all that this field would normally be used for) so I’m glad that they took my advice.
I would like to thank Dermot and everybody else including Chris who aided/attempted to aid in the patching effort. =)January 31, 2007 at 8:00 am #155002Jeff Hester
KeymasterOne thing in chat rooms that bug me more then bots are fake webcams. torseq tech is there anyway yahoo can restrict fake webcams?
The other thing I am trying to get yahoo to change is
If I got my account stolen by someone phishing or just a bad person, all they would have to do is change my password and zip code then the link Yahoo gives for forgot password would not work.
Yahoo lets people change the zip code but that is a major question for if you forgot your password. Yahoo should not let people change there zip code on there account information page. or Yahoo should not ask people for there zip code if they forgot there password.You can’t get your account back if it has been stolen becouse zip code is always changed.
If yahoo fixes the zip code problem there will be hundreds of less phishing pages aimed at Yahoo users. I got over 500 deleted since september.
The other questions yahoo asks that can’t be changed are birthdate, and secret question and answer.
February 1, 2007 at 3:53 am #155013Dermot
ParticipantMe not been american, i dont have a zip code, we dont use them
and im suppose to remember a random number i type in on registration?
i think not.
Yahoo! retain all information from initial registration no matter the change, if you can provide them with that details and similar answers like naming some buddies they will return that account.
But if you can’t give them such infomation they will not.
Phishing sites are been and should be handled browser side.
Alerting users to opening phishing sites is the best way.
reporting them and getting them deleted does little to stop them, takes 5 minutes to make another.
February 1, 2007 at 9:54 am #155001Jeff Hester
KeymasterDermot all someone would have to do if they steal your id. Is change the country that you live in and give it a zip code. The webpage to get your password back says enter the info you enterd when you registered, but that is not true. its whatever info it is when you try to find your password. Customer service would ask you for the zip code also.
Fixing this will pretty much stop phishing becouse everyone would get there accounts back.
August 7, 2008 at 11:10 pm #155033khudro
Memberhi……..first of all wana thank u guyz for those very helpful post…….:D
so…here i m…..with that old problem….exploit disconnect…i m a chatter of bd(bangladesh1)…and this things happening to rooms from last week…and still going on….i tried to look at u guyz’s post..but couldn’t understand how we can stop it….like torseq tech’s links…..i went there and found nothing……so can u guyz help us?………it didn’t stopped….how we can be saved from it?………thanks…..August 16, 2008 at 2:35 am #155005Jeff Hester
KeymasterYes, there is a exploit out that can disconnect anyone who isn’t using YTK Pro or YMLite under Gawd Mode or those using the YMSG/HTTP connection. Anyone else is a sitting duck.
-
AuthorPosts
- You must be logged in to reply to this topic.