Friday | 5 September, 2008
Computerworld
Hackers audition Yahoo Messenger exploits
Hackers are using exploits that target Yahoo's instant messaging software
Gregg Keizer 12/06/2007 08:23:30

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Hackers are now using exploits that target Yahoo's instant messaging software, security vendors said today, making it critical that users patch the Windows program immediately.

A modified version of an exploit made public last week is being used in the wild, Symantec said in an alert to customers of its DeepSight threat network. "At least one Web site is known to be hosting the exploit," said Symantec's warning. "Customers are advised to blacklist the n.88tw.net domain."

Last Wednesday, just a day after eEye Digital Security said it had found a flaw in Yahoo Messenger, a hacker posted details of vulnerabilities in two ActiveX controls distributed with the IM client, along with proof-of-concept exploit code. Later that same day, Yahoo patched Messenger and urged users to download and install the new version as soon as possible.

The SANS Institute's Internet Storm Center's (ISC) analysis noted that the in-the-wild exploit differed only slightly from the code posted last week on the Full-disclosure security mailing list. The exploit lets an attacker hijack the PC, then inject more malware into the computer. "This dropper downloaded further components, of which one was called 5in1.exe," said ISC analyst Bojan Zdrnja yesterday. "We haven't analyzed this yet but judging just by the file name, it doesn't sound good."

Over the weekend, Yahoo also added a "Security Update" warning on the Messenger home page to inform users of the new, patched software.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Email Archiving Implementation: Five Costly Mistakes to Avoid

Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links