Vulnerability Development mailing list archives

Re: icq accounts


From: zimmerman.eric () CON-WAY COM (Zimmerman, Eric - CIS)
Date: Mon, 22 Nov 1999 06:39:39 -0800


their
real IP regardless of what their settings are as long as you know some
criteria to search on which will yield their ICQ number. ICQ versions up to
the latest one are vulnerable.
 

<---------||---------> 

Eric Zimmerman 
Integrated Services Manager 
Con-Way Integrated Services 
(773) 582-6731 

PGP Fingerprint 
76F2 7012 30E2 38B1 EBD7  989C A9FB 3152 954E 2B30 

 

-----Original Message-----
From: Ömer Öztat [mailto:omero () GARANTI NET TR]
Sent: Saturday, November 20, 1999 17:12
To: VULN-DEV () SECURITYFOCUS COM
Subject: icq accounts

Hello everybody...
 
I have a question about icq and I think you'll have a word or two to say
about it.
 
By now, I know that someone with the suitable software can enter  any
unprotected icq account
 
and get the authorization to add their names to their contact list easily...
 
But I don't know if any hacker can do this on anyone's icq account :
 
In a white page search, allow only the off-line icq users to be displayed
and
 
prevent the on-line icq users from being displayed at the end of the
search......
 
Can a hacker do that kind of a thing?  
 
Are there any web sites that give information about such issues? 
 
 
Kind Regards.
 
 
 


Current thread: