Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: Possible AIM Hack?

Re: Possible AIM Hack?

From: Steven <steven_at_lovebug.org>
Date: Wed, 15 Mar 2006 19:48:01 -0500

Well like I said it could be a number of things but if you cannot logon
anymore as I said then there's a good chance of a compromise. The whole
part about not being able to logon anymore would indicate a persistent
problem that is permanent and not some problem signing on for a few minutes.
That would mean you couldn't logon right after getting kicked off, 10 mins
later, 6 hours later, 5 days later, etc. Additionally, if some server that
gives a yea/nay is on a coffe + donut break -- what would that have to do
with kicking you offline after already being authenticated?

Let's see it's been at least a day. Can you logon now? If the answer is
yes.. chances are someone didn't steal your account. If the answer is no --
I'll go with you're compromised or you forgot your password. Anyway that's
just one possible reason which defintely occurs quite frequently to people
with desirable screen names or that have pissed off someone.

Steven

----- Original Message -----
From: <Valdis.Kletnieks_at_vt.edu>
To: "Steven" <steven_at_lovebug.org>
Cc: "Travis Haymore" <thaymore_at_gmail.com>; <belka_at_att.net>;
<incidents_at_securityfocus.com>
Sent: Tuesday, March 14, 2006 8:02 PM
Subject: Re: Possible AIM Hack?

On Tue, 14 Mar 2006 16:12:50 EST, Steven said:
> logged off and can no longer logon anymore -- then that is a different
> issue. This would indicate that your account has been compromised.

Or that the authentication server has gone casters-up.

Which is more likely - that you and others that saw the same inability to
login
have *all* had your accounts compromised at the same time, or that the
server
that gives the final yea/nay was off having a coffee and donut break?
Received on Mar 16 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]