???
Moderators: Big-O Ryan, Big-O Mark
- Plasma2002b
- Extreme Groupie
- Posts: 976
- Joined: Thu Jul 18, 2002 11:36 pm
- Location: Riverside, Ca
- Contact:
well since phase doesnt seem to be too eager to tell ya how its done, i guess i will......
Everybody knows that there are a few flaws in AIM. Its just common fact. One of these known holes can be exploited.
Using some common CGI knowledge, an attacker can use any Unix based host which s/he has shell access to, wether it be typing the commands in one by one, or simply loading them from a scripted list to be executed, the attacker can manipulate the Oscar server to redirect certain im messages back upon itself and then out after a givin callback time can spit the messages out to any other person with a valid SN.
Whats happening is that the messages get put in limbo for however long the attacker sees fit... looping the messages upon the Oscar's localhost gives the attacker one good thing..... multiplication. As soon as s/he wants to let the loop end and spread the messages back to whomever, the attackee, or victim, gets an insane amount of redundant and not so redundant messages.
A few simple pieces of coding can be stuck in to make it seem as if these messages are coming from thousands upon thousands of different people, or simply from one person.... or maybe possible a group of simmilar SN's.
The fact of the matter is this..... your connection, client software, memory, processor, or whatever just cant handle the sheer amount of rebounded information coming from one place all in that short period of time. Like it or not, its gonna take something down from your computer.
Everybody knows that there are a few flaws in AIM. Its just common fact. One of these known holes can be exploited.
Using some common CGI knowledge, an attacker can use any Unix based host which s/he has shell access to, wether it be typing the commands in one by one, or simply loading them from a scripted list to be executed, the attacker can manipulate the Oscar server to redirect certain im messages back upon itself and then out after a givin callback time can spit the messages out to any other person with a valid SN.
Whats happening is that the messages get put in limbo for however long the attacker sees fit... looping the messages upon the Oscar's localhost gives the attacker one good thing..... multiplication. As soon as s/he wants to let the loop end and spread the messages back to whomever, the attackee, or victim, gets an insane amount of redundant and not so redundant messages.
A few simple pieces of coding can be stuck in to make it seem as if these messages are coming from thousands upon thousands of different people, or simply from one person.... or maybe possible a group of simmilar SN's.
The fact of the matter is this..... your connection, client software, memory, processor, or whatever just cant handle the sheer amount of rebounded information coming from one place all in that short period of time. Like it or not, its gonna take something down from your computer.
stfu
He most likely used either aim invader or cybermass to crash your computer rokbus
- Master Jedi
- Guru
- Posts: 1161
- Joined: Sat Jun 15, 2002 10:34 pm
- Contact:
Who is online
Users browsing this forum: No registered users and 0 guests