
Hackers get friendly on IM
Published: 10 March 2004 09:00 GMT
Microsoft has revealed three new vulnerabilities in its software, including the first to affect MSN Messenger 6.0, and is urging customers to patch their systems now.
Two of the vulnerabilities are considered medium-level risks, while the third presents a medium- to low-level risk, according to security software specialist Symantec and others. Three separate patches to repair the flaws - which affect different pieces of software - have been released and are available for download. The identification of the vulnerabilities came on Wednesday as part of Microsoft's regular security bulletin process.
Later, the software giant will also send notices about the Messenger patch through MSN Messenger itself, said Stephen Toulouse, security program manager for the Microsoft Security Response Center.
The vulnerability in MSN Messenger versions 6.0 and 6.1 could let an attacker view the contents of a victim's hard drive during a chat session with the victim.
Attackers "could view files through MSN Messenger on their computer," Toulouse said. "They can do it, and you are not necessarily aware of what they are doing."
Users who do not block anonymous callers are most vulnerable to the exploit. If anonymous callers are blocked, the attacker has to be identified on the victim's address list. To obtain particular information, such as credit card numbers, attackers have to trawl the hard drive, said Toulouse.
Oliver Friedrichs, senior manager for Symantec's security response team, said that victims don't actually have to be in conversation with the attacker. As long as the user permits anonymous callers to send messages, an attacker could come in and peruse Quicken files or other identifiable files that could likely contain sensitive data. However, most people block that function, so random attacks will likely be rare, he said.
The second medium-level risk could allow a hacker to take over a system by executing Internet Explorer code through a flaw in Outlook 2002.
A computer has to be configured in a particular manner, though, said Toulouse. The user has to set Outlook Today as the Outlook home page.
"If you go to Outlook through your inbox, you are protected," he said.
The third flaw allows attackers to instigate a denial-of-service attack against servers running Windows Media Services 4.1. The vulnerability exists because of the way Windows Media Station Service and Windows Media Monitor Service, components of Windows Media Services, handle TCP/IP connections. If an attacker sent a particular sequence of packets to a server running Media Services 4.1, it could interrupt any video streams.
Michael Kanellos writes for CNET News.com
By 2012, we predict the main medium carrying intelligence on our targets will be via the internet. We recognise this fact and are investing heavily ...
Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...
Great role within leading IT Vendor / innovator - Apply / Call /Email now for fast response. Storage SAN NAS Professional Services Implementation ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Momentum Webcast: Assessment and Deployment Best Practices for Windows Vista (Level...
Momentum Webcast: Moving Forward With Windows Vista SP1 (Level 100)
Microsoft Office System Webcast: Tips and Tricks for Office 2008 for Mac: Incredible...
Microsoft Office System Webcast: Compatibility Tips for Office 2008 for Mac and the...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... ZX Spectrum nostalgia, Mac attack, tag a bag… Reader Comments of the Week
Steve Ranger Editor's Blog: Home computing from Acorn, Amiga and Amstrad, to the ZX Spectrum Nostalgia 2.0...