Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: AOL IM 4.7 d0s 0-Day
From: Tony Lambiris <methodic () slartibartfast angrypacket com>
Date: Tue, 2 Oct 2001 11:33:01 -0700

Proof of concept code up at http://sec.angrypacket.com

check under the "code" section.

On 10.01.01, Matthew Sachs <matthewg () zevils com> wrote:
I just saw this with my custom AIM client.  It's an IM consisting of
a repeated sequence of "<!-- " (sans quotes).  I tested it against
WinAIM 4.7.2480 and it does indeed produce the crash you described.

-- 
Matthew Sachs, the original nonstandard deviant
matthewg () zevils com        http://www.zevils.com/
GPG key: 0x600A0342   PGP key: 0x93EA1151

-- 
Tony Lambiris [methodic () slartibartfast angrypacket com]
   http://www.openbsd.org && http://www.openssh.com
       "Anyone who truly understands the power 
         of UNIX wouldn't use anything else."


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]