OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Mark Coleman (mcolemanuniontown.com)
Date: Thu Jan 03 2002 - 15:41:22 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    AIM fixed? Can anyone confirm?

    http://www.msnbc.com/modules/exports/ct_email.asp?/news/680950.asp

    Thanks,

    Mark C.

    ----- Original Message -----
    From: Matt Conover <shokdataforce.net>
    To: Paul Schmehl <paulsutdallas.edu>
    Cc: <bugtraqsecurityfocus.com>
    Sent: Wednesday, January 02, 2002 12:00 PM
    Subject: Re: AIM addendum

    > > The temporary solution you provide would only protect you so long as all
    > > the buddies on your list were not compromised. As soon as one buddy is
    > > compromised, then you are vulnerable *through* that buddy. Or am I not
    > > clearly understanding this exploit?
    >
    > Yes, which is why in the original advisory we recommended AIM filter be
    > installed. This will block the attack from anyone. So only allowing your
    > buddies to contact you in addition to installing AIM filter will keep you
    > secure until a new version of AIM comes out.