what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

AIM-dos.txt

AIM-dos.txt
Posted Mar 4, 2000
Authored by Cruz

AOL Instant Messenger can be crashed remotely with upper ascii symbols, version 3.5 tested, others most likely vulnerable. Unofficial patch available on the homepage, here.

tags | exploit, denial of service
SHA-256 | 85acb684e56bd11b112a7bc134dd69c34a46d09d9700f0f57f01d2e2eaa2c47f

AIM-dos.txt

Change Mirror Download
As all Ascii-Symbols can be displayed in &#XXX; format, where XXX are
numbers from 0-255, AIM seems not to check the XXX for higher values
and some strings above 255 result in aim crashing completly or in part.

E.g. the string ̂ will result in crashing the whole aim, but ̃
will crash only the instant message window (̃ was only tested once
by me).
It will crash the AIM of the attacker too, because AIM displays the string
in the attacker-Instant Message, so the attacker-AIM also tries to convert
it and errors.

There is already an unofficial fix available, which can be downloaded at my
hompage: http://laugh.at/cruz
The fix is an edited ate32.dll, which should be copied to the aim directory.
With it, aim doesnt try to convert "&#XXX;"-type of strings anymore, a
minimum drawback (note: with that fix, the attacker can use this exploit to
crash other unfixed AIMs, but wont crash his/her own AIM).

Affected versions: I tested this only on 3.5+ versions of AIM, but all other
versions are most likely affected too.

-cruz
http://laugh.at/cruz

______________________________________________________
Get Your Private, Free Email at http://www.hotmail.com


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close