Vulnerability Development mailing list archives

RE: possible AIM dos?


From: "leon" <leon () inyc com>
Date: Thu, 11 Oct 2001 08:56:59 -0400

You are only allowed to warn someone 35 percent in one "session".  Then
if you restart (aim) you can warn them another 35 percent however they
have to respond to your messages for this to effective.

HTH

Leon

-----Original Message-----
From: John Scimone [mailto:jscimone () cc gatech edu] 
Sent: Tuesday, October 09, 2001 7:15 PM
To: vuln-dev () securityfocus com
Subject: possible AIM dos?

After reading this outdated article regarding AOL Instant Messenger's
"warn" 
feature:

http://www.attrition.org/security/denial/w/aim-warn.dos.html

I began to wonder what type of restrictions were put on it.  Does anyone
know 
what is stopping someone from registering multiple screen names, then
sending 
warnings from each of those names, all targeted at the same user thus
keeping 
that user at a 100% warning level denying them the instant messenger
service 
for the most part? 
any thoughts are appreciated.
thanks.

John Scimone


Current thread: