Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Suggested fix for AIM hole has back door and spyware

January 9, 2002 12:00 PM ET

IDG News Service - Software recommended last week by security group w00w00 Security Development to plug a hole in America Online Inc.'s Instant Messenger (AIM) actually opens a user's system to hacker attacks and can direct the user's Web browser to pornographic Web sites, w00w00 said yesterday.

The security group was the first to publicize the hole in AIM last week (see story), prompting Dulles, Va.-based AOL to take action and correct the problem on the server side within a few days (see story). In its initial warning, w00w00 advised users to download and install a third-party program called AIM Filter for immediate protection. But that software comes with its own security problems, a member of the w00w00 team wrote in a posting to the Bugtraq mailing list late yesterday.

"At the time, Robbie Saunders' AIM Filter seemed like a nice temporary solution. Unfortunately, it instead produces cash-paid click-throughs over time intervals and contains backdoor code," Jordan Ritter wrote. The click-throughs direct the user's Web browser to advertisements using Saunders' referral code, generating commission payments for him.

W00w00 now offers a cleaned-up version of AIM Filter without these security holes, Ritter wrote. The problems with the software, which is designed to block certain AIM functions, were discovered Jan. 5, when Saunders released the source code for his filter, Ritter said in the Bugtraq posting, apologizing for the error.

AIM Filter creator Saunders said in a statement on his Web site that AIM Filter allows him to remotely obtain a user's Internet Protocol address and AIM build number. It also allows him to shut down AIM Filter on a user's system and open five "embarrassing Web sites," the statement said. The porn Web sites pop up only when AIM Filter is launched, not at time intervals, he stated.

It's unknown how many people installed AIM Filter. One AIM user in a newsgroup asked w00w00 for more detailed instructions on how to remove AIM Filter.

A buffer overflow vulnerability existed in the shared game feature of AIM, AOL said Jan. 2. Attackers could access a user's system by exploiting the vulnerability, according to w00w00.

Related stories:




Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...