FW: AOL IM 4.7 d0s 0-Day

From: leon (leon@inyc.com)
Date: 09/30/01


From: "leon" <leon@inyc.com>
To: <vuln-dev@securityfocus.com>
Subject: FW: AOL IM 4.7 d0s 0-Day
Date: Sat, 29 Sep 2001 19:34:11 -0400
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAA+8DoZCJ8SEaYk5pn4rrIf8KAAAAQAAAAIbeDDw95h0itTIuIK3haMwEAAAAA@inyc.com>



-----Original Message-----
From: leon [mailto:leon@inyc.com]
Sent: Saturday, September 29, 2001 7:32 PM
To: 'vuln-dev@securityfocus.com'
Subject: AOL IM 4.7 d0s 0-Day

Hi everyone,

There is currently a 0-Day exploit for aol im that allows anyone to boot
you just by sending an im, It is similar to the old &#770; bootstring.
I have managed to get a debug of it along with a capture of the packets.
Can anyone help me figure out how to defend against this or in the very
least explain what is going on (since I don't have coding skillz). I
managed to capture the packets with iris 2.0 and they are now .cap
files. Can anyone help me A) recreate the exploit & B) tell me how to
defend against it?

Cheers,

Leon

Please mail me offline for the debug









Relevant Pages

  • FW: AOL IM 4.7 d0s 0-Day
    ... Forget it blue boar those are the wrong packets. ... There is currently a 0-Day exploit for aol im that allows anyone to boot ... I have managed to get a debug of it along with a capture of the packets. ... Can anyone help me figure out how to defend against this or in the very ...
    (Vuln-Dev)
  • Re: AOL IM 4.7 d0s 0-Day
    ... AOL IM 4.7 d0s 0-Day ... run ethereal or something and get a proper packet log, that way if iris is ... > I have managed to get a debug of it along with a capture of the packets. ... > Can anyone help me figure out how to defend against this or in the very ...
    (Vuln-Dev)
  • Re: chat logging in AOL IM and battle.net?
    ... >AOL IM and games on ... Are there any tools anywhere that can capture chat ... talk to your child and learn to trust them. ... consequences when you child discovers you've been spying on them. ...
    (comp.security.misc)
  • Re: Vista Circles of Life and Death
    ... Tell me if AOL is so great why are they steadily losing customers and have ... Why do you flame McAfee as "bloatware" with no evidence to support your ... Maybe someone else can defend your idiocy if you're stupid enough to ignore ...
    (microsoft.public.windows.vista.general)
  • chat logging in AOL IM and battle.net?
    ... monitoring my childrens use of the internet. ... AOL IM and games on ... I wonder if a keystroke capture program might do the trick? ...
    (comp.security.misc)