• Pardon our dust… Learn about the changes coming at BigBlueBall
  • Instant Messaging
  • Social Networks
  • Mobile
  • Tutorials

BigBlueBall

  • Home
  • Blog
  • Archives
  • Forums
    • Forum Home
    • Home
    • Learning
    • Money
    • Wellness
    • Community
    • Latest Topics
    • Topics with No Replies
    • Most Popular Topics
  • About
  • Contact Us

ICQ 6.5 HTML Injection Bug

August 19, 2009 by Jeff Hester Leave a Comment

ICQThe venerable IM is vulnerable. SecuObs.com reports that popular instant messenger ICQ (“I seek you”), version 6.5 is vulnerable to HTML-injection attack.

What does this mean?

The incoming message window in the vulnerable ICQ client works like a mini web browser. An attacker can try to exploit the vulnerability by sending specially crafted message to the remote ICQ client. The malicious message can contain text data which will be interpreted and displayed in the incoming message window as a HTML code. Potentially an arbitrary HTML code could be injected.

There are two risks that have been identified:

1.  Information disclosure

For example, an attacker can inject <IMG> tag that could lead information disclosure (such as remote client’s IP address, browser version, OS version, etc.)

2.  Spoofing

An attacker can spoof ICQ client software’s system messages, interface elements (buttons, links) in the message window, etc. For example, it could be used for forcing of the ICQ users to click on attacker’s malicious link.

The vulnerability exists in the lastest build of ICQ 6.5, and may affect older versions as well.

As of yet, ICQ has not issued an update to fix this vulnerability. To be safe until they do, I suggest using an alternate, compatible IM client  such as Trillian, Adium, Pidgin or Digsby.

HTML-injection vulnerability exists in official ICQ client software. Incoming message window in the vulnerable ICQ client has a web browser nature. An attacker can try to exploit the vulnerability by sending specially crafted message to the remote ICQ client. The malicious message can contain text data which will be interpreted and displayed in the incoming message window as a HTML code. Potentially an arbitrary HTML code could be injected.
There are two impacts of the vulnerability has been detected:
1.  Information disclosure
For example, an attacker can inject <IMG> tag that could lead information disclosure (such as remote client’s IP address, browser version, OS version, etc.)
2.  Spoofing
An attacker can spoof ICQ client software’s system messages, interface elements (buttons, links) in the message window, etc. For example, it could be used for forcing of the ICQ users to click on attacker’s malicious link.
Maybe other impacts are possible.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on Pinterest (Opens in new window) Pinterest
  • More
  • Share on Reddit (Opens in new window) Reddit
  • Email a link to a friend (Opens in new window) Email
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Tumblr (Opens in new window) Tumblr

Like this:

Like Loading…

Related

Filed Under: ICQ Tagged With: ICQ, Instant Messaging, instant messaging, security

About Jeff Hester

I use technology, community and sound advice to build a better life. I am an advocate for social media and knowledge management, an avid hiker, father, grandfather, husband, author, speaker, dog walker, web developer and damn good listener. You can also find me on Flickr, Instagram, Twitter, LinkedIn, Google+ and Facebook.

Leave a ReplyCancel reply

About BigBlueBall

I am a technology geek, yet I gladly leave it behind to spend more time hiking the local trails or traveling the world. I am constantly experimenting, in search of new ways to improve my life. I believe in living out loud, and sharing what I learn with you.

My goal for BigBlueBall is simple: give you no-bull advice that you can use to improve your life.

Google+

Top Posts & Pages

  • Setting Up a Smart Home
  • Contact Us
  • Making Moving Easier - A Look at Sortly
  • About BigBlueBall
  • Out With the Old, In With the New
  • Top 10 Instant Messaging Apps Worldwide
  • BigBlueBlog
  • Windows Messenger is Dead... Long Live Skype

Recent Forum Replies

  • Who’s here? Can you still sign-in?
  • Project “BigBlueBall Revival”
  • Heard a rumor about AIM chat client begin discontined in the next few months. .
  • AIM Version 8
  • AIM Version 8

About BigBlueBall

Pardon the dust... but we are shaking things up at BigBlueBall. The site has been through a couple of evolutions, and this marks the latest and best yet!

Are you sick and tired of "Top 10" lists that don't really help you make decisions that will improve your life? That's a pet peeve of mine, too, and I'm doing something about it.

No more crap about the myriad of choices out there. Just the best choice. The right choice. The one fill-in-the-blank that rules them all. And all of them are vetted by us... through personal use and experience. These are the tools, the gadgets, the apps, the websites and the lifehacks that we use every day. No bullshit. Just good advice for better living.

Recent Posts

  • Setting Up a Smart Home
  • Making Moving Easier – A Look at Sortly
  • Top 10 Instant Messaging Apps Worldwide
  • Are You Twice As Likely to Sleep Naked?
  • Out With the Old, In With the New
  • Instagram Web Profiles Are Here
  • Windows Messenger is Dead… Long Live Skype

Tags

AIM android aol Apple beta BigBlueBall Blackberry chat comic digsby emoticon enterprise Facebook google Google Talk humor ICQ imbooster infographic instant messaging Instant Messaging iPhone Mac Meebo microsoft Mobile msn MySpace nokia security skype SMS social networking Social Networks sunday funnies sunday funny trillian Twitter video VoIP Windows Live Messenger Windows Live Messenger windows mobile yahoo youtube

Copyright © 2026 · Metro Pro Theme on Genesis Framework · WordPress · Log in

Loading Comments...
%d