Feeds

AOL buddy-hole fix has backdoor

'You've got bugs'

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

A member of w00w00, the security enthusiasts who first reported the AOL Instant Messenger (AIM) games request vulnerability, has alerted users that a fix the group recommends has its own backdoor.

Apparently, the AIM Filter by Robbie Saunders which w00w00 had recommended is infected, group member Jordan Ritter disclosed on the Bugtraq mailing list late Tuesday.

"At the time, Robbie Saunders' AIM Filter seemed like a nice temporary solution. Unfortunately, it instead produces cash-paid click-throughs over time intervals and contains backdoor code combined with basic obfuscation to divulge system information and launch several Web browsers to porn sites," Ritter wrote.

"We only took the time to verify that it blocked the attack, since an analysis of AIM filter wasn't our priority. Mea culpa."

w00w00 has since devised a clean version of AIM Filter.

Meanwhile, Saunders says on his Web site that the advisory is overstated.

"The filter enables the user on the screen name 'robbieiship' to use two admin commands: 1) get your IP and build number [in case I should feel like reporting you to your ISP]; 2) shut down your AIM Filter and open five embarrassing Web sites [in case you mess with my friends]."

"The cash-paid click-throughs are because I need money and they only go in once (when you open the filter) and not on time intervals like w00w00 claims."

A subsequent post to Bugtraq by w00w00 member Tim Yardley supports part of this claim, but not all of it.

"The query user packet would send a message to Robbie Saunders with the IP address of your machine. The DC [direct connection?] packet would open four Web browsers to various porn sites."

"The DC loop packet would send the DC packet in a message over and over, until length of 7900 was reached (max transmission size I guess). On connect, the software would connect to two different sites using Robbie's click ID (to generate money for him). There was also a timer that did this same thing."

So there we have two slightly different accounts, but general consensus that AIM FIlter isn't a terribly dangerous thing, if not terribly polite.

As for those who installed AIM Filter, so far as we know at the moment, removing it is all that's required to defeat it. We will of course follow up if anything further emerges. ®

Related Stories

AIM gives up control of Windows machines
AOL bungs buddy-list security hole

Beginner's guide to SSL certificates

More from The Register

next story
ONE MILLION people already running Windows 10
A third of them are doing it in VMs, but early feedback focuses on frippery
Sign off my IT project or I’ll PHONE your MUM
Honestly, it’s a piece of piss
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Torvalds CONFESSES: 'I'm pretty good at alienating devs'
Admits to 'a metric ****load' of mistakes during work with Linux collaborators
Sway: Microsoft's new Office app doesn't have an Undo function
Content aggregation, meet the workplace ... oh
Do Moan! MONSTER 6-day EMAIL OUTAGE hits Domain Monster
Customers freaked out by frightful service
Ploppr: The #VultureTRENDING App of the Now
This organic crowd sourced viro- social fertiliser just got REAL
Return of the Jedi – Apache reclaims web server crown
.london, .hamburg and .公司 - that's .com in Chinese - storm the web server charts
NetWare sales revive in China thanks to that man Snowden
If it ain't Microsoft, it's in fashion behind the Great Firewall
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.