Re: AIM addendum

From: Paul Schmehl (pauls@utdallas.edu)
Date: 01/02/02


Date: Wed, 02 Jan 2002 13:42:08 -0600
From: Paul Schmehl <pauls@utdallas.edu>
To: Matt Conover <shok@dataforce.net>, bugtraq@securityfocus.com

The temporary solution you provide would only protect you so long as all
the buddies on your list were not compromised. As soon as one buddy is
compromised, then you are vulnerable *through* that buddy. Or am I not
clearly understanding this exploit?

--On Wednesday, January 02, 2002 9:17 PM +0300 Matt Conover
<shok@dataforce.net> wrote:
>
> 2. A temporary solution to this vulnerability is:
> 1. Go to your Preferences
> 2. Go to the Privacy section
> 3. Click "Allow only users on my Buddy List" under "who can contact me"
>
> This will disable the vulnerability because you will appear signed off to
> anyone not in your buddy 3.

Paul Schmehl (pauls@utdallas.edu)
Supervisor of Support Services
The University of Texas at Dallas
AVIEN Founding Member



Relevant Pages

  • Re: East Plains Open Sectionals
    ... known the captain of the Louisville team for years. ... were) good buddies, ... Option 3, don't say a word to your good buddy, go ...
    (rec.sport.disc)
  • Re: Got hate?
    ... something, probably pussy. ... everything you have, and buddy, it ain't worth sharing. ... Notice your buddies, ...
    (alt.guitar.amps)
  • Re: Hi fellow MCPs
    ... > that's it, buddy boy. ... now i am MAD!! ... i am going to tell my verisign ...
    (microsoft.public.cert.exam.mcse)
  • Re: AIM addendum
    ... > the buddies on your list were not compromised. ... then you are vulnerable *through* that buddy. ... which is why in the original advisory we recommended AIM filter be ... buddies to contact you in addition to installing AIM filter will keep you ...
    (Bugtraq)
  • Re: Is Lacostawhatever/aka Skillz the Dwight Schrute of this newsgroup?
    ... I called him Buddy. ... Proper response was sit the fuck down and shut the fuck up. ... Sounds like you need to find better buddies to hang out with! ... If you didn't like the first suggestion, ...
    (rec.gambling.poker)