Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

RE: MSN Messenger PNG Image Buffer Overflow Download Shellcoded Exploit
From: "Andrew Hunter" <andiroohunter () msn com>
Date: Thu, 10 Feb 2005 09:48:37 +0000

Ok after switching to MSN 6 still couldn't load the image as my display picture. It turns out that the instructions provided with this file are wrong! You have to send the victim the image via the file transfer mode on MSN.

I have tested this and can varify that it works. It isn't an auto exploitation, the user has to click the link to view the file, at which point there msn will freeze and a .exe will be dropped onto the system(assuming HTTP isn't blocked by the firewall). The victim will know that something dodgy has happened since in each case their MSN closes/freezes.



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]