Security Basics mailing list archives

Private IP address with yahoo messenger


From: "Vivek P" <iamherevivek () gmail com>
Date: Thu, 24 May 2007 13:42:00 +0530

Hi

I had been testing on this for quiet some time now. In versions of
yahoo messenger before 6, when i transfer a file >2 mb and try netstat
-a -n from CMD on windows machine, i was able to get the IP address
(internal) of the person at the other end !!

Yahoo did some patches in the latest editions but, i have been
informed by my testing team that burp proxy can get the target IP
(internal) if you have it installed, when using latest edition to do
file transfer,

Also when you do calls using messenger point to point connection is made.

it is like

normal chat
a <-------->Yahoo server(s) <-------> b

Lengthy processes (filetransfer) (calls) etc.
a<------->Yahoo authenticates at interval<----->b
a<------->b //Direct connection.


I think it would help, please revert so that i can get you some video
demonstations to prove my experiment.


Thanx
--
Vivek P Nair
Vice President, Technology
ASG
www.vivekpnair.com
iamherevivek () gmail com
d3@d Br@iN
"i thought i would change the world, But they wouldnt gimme the source Code !!"


On 5/23/07, Alcides <alcides.hercules () gmail com> wrote:
Hi list,
I was wondering to have any clue on this.
While having a chat session with somebody in yahoo messenger, how is
it possible to obtain his/her Private IP address if that person is
behind a Router and/or a Firewall (NATed)?
Moreover,
Is there any way that he/she can hide successfully (behind the NAT or
something else)so that NO internal IP address is revealed?
Thanks.
Warm regards.


Current thread: