Vulnerability Development mailing list archives

"cheesy" aim dos


From: "leon" <leon () inyc com>
Date: Thu, 11 Oct 2001 09:04:03 -0400


Ok I got a dos for you guys.

If you have someone's screename and they are not logged on you can
prevent them from logging on quite easily.  Try to log on with their
name and a fake password, after about 10 or so attempts it will give you
a message that says rate limited you are trying to sign on too quickly.

When they try to log on with the real password they will be denied
service.  This is cheesy in the sense that you every 10 - 15 minutes you
will have to mess up the password at least once after the initial
"attack" (if you can call it that).

However it is still very annoying if someone has one user name and they
prefer that over others.

Hope that helps.

Regards,

Leon


Current thread: