Forum Replies Created
-
AuthorPosts
-
Pitbull On Roids
MemberWhat language would you be developing this tool in ? #2 has been possible for quite a while now and can/will be misused. #3 sounds like a stalking option which would only give you general status of their online presence and virtually no hard-to-obtain info; let alone wouldn’t normally be used for legit purposes. #4 is called a mass pm and there are programs out there that let you mass pm people in chat without even being on your buddy list. #5 could be an offline message and you could have archiving enabled to read it later. PM text logging and chatroom text logging isn’t new. Be more specific with what you are going to try to create. These features wouldn’t be helpful to me. Sorry. Maybe to others though.
Pitbull On Roids
MemberHmmmm……. Could be a variety of things. Temporary solution for now…… download a file-splitter and you can break up whatever you’re sending him into 1mb. chunks if needs be. Then, he could assemble it fully on the other end. This actually works quite well.
Pitbull On Roids
MemberYet another mistake, lol. “It’s the default ones that just come in the .gif format which don’t animate. I was had that wrong.”
Correction:
It’s the default ones that just come in the .gif format which DO animate in/out of messenger.FINAL CORRECTION, both sets come in .bmp and .gif………… The only exception to this is that the hidden default emoticons only come in .gif and aren’t in .bmp format. There, sorry for all of the insanity. I think I need to go to bed now. I pull all-nighters way too much ! :p
Pitbull On Roids
MemberOops….. my bad. The sexual ones do infact come in .gif format. I had to look again to make sure. They also come in bitmap (.bmp) format as well. It’s the default ones that just come in the .gif format which don’t animate. I was had that wrong. The default set doesn’t come in bitmap format but it wouldn’t be hard to convert them to a still image .bmp file…. not that anyone would care to do this anyway cuz it wouldn’t be animated. 🙂
Pitbull On Roids
MemberYup. I’ve got both set’s installation files. Right now I’m using the sexual set…… but I’ve got the backup of the default ones. The sexual set only comes in bitmap (.bmp) format in your messenger folder. However, yahoo messenger client reads the bitmaps still pics as animated .gifs and displays them that way. You can get the default ones in .gif format in your messenger folder. Their animations will work in/out of messenger unlike the bitmapped sexual set. These have to be read by messenger for animation……. unless you’re clever enough to know how to work around that. 😎
Pitbull On Roids
MemberNo problem Oreo. Black Ice…….errrrr…….. not a big fan at all for too many reasons. As far as I’m concerned their exploitful history isn’t very impressive. From what I know in the security field….. Sygate pro 5 is the best there is for a Windows machine currently. I attend ITT-Tech in Dayton, Ohio and they use Sygate on all there computers as well. With Sygate Pro you get a whole arsenal of goodies like dll-authentication, anti-ip spoofing, anti-mac address spoofing, and a crapload more stuff that makes the firewall the best that there is, imo. It’s not only an awesome stateful packet inspecting firewall suite but a full blown Intrusion Detection System as well. It is a hybrid of both. It also has a 30-day free trial on it. Whatever works though works. Different strokes for different folks. Glad to be of help Oreo. Even with a firewall like Sygate, and Y!TunnelPro in your defense, there still are ways to get booted from messenger. The biggest way is through using exploits in voice chats. When you initiate voice chat two of the known and documented udp ports 5000 – 5010 are opened locally on your computer to receive yahoo’s audio data stream from the actual voice server. Yahoo does the poorest job of validating this actual data stream and it’s contents and making sure that the data is actually coming from the source ip address that it’s supposed to (yahoo’s voice servers). So, pretty much, anyone with some udp protocol knowledge and a bit of programming knowledge can probe for exploits, find one, and implement it into a program (usually in vb6 for ease of use) based around the udp protocol. Once the prog is written, if correctly done, it can inject it’s customly written udp malformed packets into yahoo’s voice stream data and have it broadcasted to the entire targeted room giving ypager errors to everyone in there running the targeted ver. and build of messenger that the exploit(s) effect. This is a packeting denial of service attack which have been around for years now. Luckily, blocking these udp ports won’t deny you voice chatting on messenger. Yahoo Messenger reverts to the tcp protocol when it realizes that it’s default udp port range is blocked off and chooses a random tcp port for the audio data stream to be received locally. TCP packets are much harder to write so hackers or potential hackers normally don’t want to bother with even trying to exploit you. UDP doesn’t establish a connection-state so the attackers ip wouldn’t be revealed to the targets as well as this proto doesn’t use congestion control that would slow the data down from hitting the potential victims. UDP also supports multicasting which would be ideal for dos attacks. So, udp can be a dangerous protocol when the malicious packets are crafted right. Having your voice chats over the tcp protocol is much safer as this proto actually does error-control & correction and validation…… not to mention that hackers would never be able to guess which tcp port is receiving the audio data on your end normally. Without this knowledge, they wouldn’t know which port(s) running the service to target. Only thing that kind of sucks about tcp protocol is that they use congestion control and this can bog down streaming data communication, which at times, you can notice in voice chats on low-band dialup connections. UDP is the most ideal for streaming data because it lacks congestion control…meaning less lag between your bi-directional connection. Just thought that some people might want to know this as firewalls wouldn’t stop some of these exploit-boots in certain situations using new malformed packeting techiniques targeting certain ports. Everyday someone is figuring something new out that can be potentially malicious. The question is……. will it ever be exploited ? It all depends on who has the knowledge and what their intentions are. Knowledge is power……. no doubt about it.
Pitbull On Roids
Member😎 If anything, that’d be a weakness for them……. for me to be on their list. For others, probably not. There’s more than one of these programs out publicly and they’ve been around longer than you’d think. Just because you are on their list doesn’t mean that you are being hunted or potentially hunted, lol. They can track your online/offline status and your chats that you go to and that’s about it. If you have Y!TunnelPro up and configured to block outsiders pm’s, invites, and buddy & cam req’s…… you don’t need to worry at all about anything other than maybe a stalker that can’t do jack to you. They wouldn’t be able to obtain your IP currently either as if you’re using the newest Y!TunnelPro V1.1 Build 164, your ip and profiles are inaccesible to hackers and your ip is masked as 187.64.187.64 (in a voice chatroom). All of their attempts would be rejected. Just don’t do p2p cam sessions, file xfers, IMVironments, and pm’s with non-buddies if you wanna be on the safe side. These would reveal your true ip to them. Restrict all access just to buddies on your list. If you’ve got the newest Y!TunnelPro, make sure you have all anti-boot options turned on like “block direct connections to messenger” and have “hide my ip and profiles” enabled. Put up a good firewall like Sygate Pro 5 and configure it to block udp ports 5000-5010 to block mic boot exploits that use yahoo’s voice chat udp data streams like yacscom.dll and the other ypagers like myyahoo.dll and tsd32.dll to name some. Having the “prevent loss of voice on mic” option in Y!TunnelPro enabled will do this too. Logon as “invisible” if you don’t want the person seeing your online presence. If you suspect a certain person has you on their list……. deny-a-buddy them. If someone has me on their list…… they’d be a victim as they’d be forced to see my status if they opened a pm to me. They’d end up catching an iframe code and would go bye bye if they weren’t using the newest Y!TunnelPro (as it blocks status msg iframes). Sometimes, my status messages aren’t nice.
Basically, I’m telling you this……… Not a big deal. As for these program’s reasoning…… only could be malicious or they would have asked you for permission. Just make sure you’re properly protected because Yahoo can be a dangerous place at times. Hell, who knows, you might even become buds with a stalker at some point down the road. Could turn out to be a friend. 😀
-
AuthorPosts