Welcome | Sign In
TechNewsWorld.com
Security

Webcam Chats With Strangers Could Trigger Yahoo Messenger Attack

Print Version
E-Mail Article
Reprints
Webcam Chats With Strangers Could Trigger Yahoo Messenger Attack

McAfee's Avert Labs has called out a zero-day trick that could be used by hackers to attack users of Yahoo Messenger. While a fix isn't ready at this time, end users can easily avoid the problem if they don't accept webcam invites from untrusted sources. The threat is the latest in a growing trend of IM-based attack vectors.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

McAfee has confirmed a zero-day vulnerability in Yahoo's (Nasdaq: YHOO) popular instant messaging solution, Yahoo Messenger. McAfee's Avert Labs is a security research firm designed to tackle security issues as soon as they trickle into the world, and the crew first noticed the potential flaw on a post on a Chinese-language security forum.

The flaws, according to McAfee, allows for a user-assisted remote code execution attack, meaning an IM user has to act in response to a prompt from a hacker in order for the attack to proceed.

McAfee Avert Labs reproduced the vulnerability on Yahoo Messenger version 8.1.0.413.

Piling On the Heap

"It seems like a classic heap overflow, which can be triggered when the victim accepts a webcam invite," explained Avert Labs' Wei Wang. "Note that this vulnerability is different from the recently patched one in June, which exploited the Yahoo Webcam ActiveX controls."

McAfee has alerted Yahoo of the issue, the research firm said. Yahoo posted a fix of the webcam ActiveX in June. While a fix isn't ready at this time, end users can easily avoid the problem if they don't accept webcam invites from untrusted sources.

For its part, McAfee has also released its network intrusion protection system IntruShield signatures, which protect Yahoo Messenger users from the threat.

Growing IM Issues?

Yahoo Messenger was the victim of the above-mentioned webcam ActiveX attack earlier this year, but have there been many others?

"Prior to 2002, 2003, there were only a couple dozen IM-based threats in total, but now sometimes we see upwards of 70 or 80 new ones a month," Dave Marcus, security research and communications manager for McAfee Avert Labs, told TechNewsWorld.

"It's definitely been a growing area for a couple of years, which really makes sense when you consider how many more people now are using IM as a communication tool than in past years," he added.

IM Vigilance

What's the best way to avoid IM-based vulnerabilities?

"Some of the same best practices with basic e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse safety transition to IM, too," Marcus said.

"You've got to be careful of people sending you stuff who are not on your buddy list. A lot of [nefarious] people like to send links that are not correct, that are fake links to sites with malware, spyware or trojans," he explained. "Not accepting messages from people outside of your buddy list is a first place to start."

Despite this, there are a lot of tools in the underground that let hackers capture IM traffic between parties, which could also help them try to fake the identity of someone an IM user is friends with. To make matters worse, there's a growing trend of hackers using malware to steal identities and glean personal information for profit.

For even stronger protection, Avert Labs recommends that people block outgoing traffic on TCP port 5100 until Yahoo patches the vulnerability.


Print Version E-Mail Article Reprints More by Chris Maxcer


More by Chris Maxcer

The Gphone That Could Catch My Eye
November 20, 2009
Rumors are cropping up that Google is preparing to sell its own Gphone -- an Android handset using Google-branded hardware. There are some reasons to doubt it will happen, of course, but the possibility is intriguing. What would Google have to build to make something worthy of an iPhone fan's attention?
Apple's House Rules Won't Be the Death of App Development
November 13, 2009
Facebook's iPhone app is one of the most popular wares the App Store has ever carried. But its developer, Joe Hewitt, says he's through with it, stating that Apple's review policies are starting a bad precedent for other platforms. However, good apps from talented developers will always find platforms, and Apple's policies won't prevent that from happening. They may even help.
Let's Give the iPhone Hackers a Big Round of Applause
November 06, 2009
It's safe to say most Apple customers are satisfied living in the walled-off ecosystem that the company has created for products like the iPhone. Still, it's good to know that it is possible -- and relatively easy, even -- to bust through those walls if one should ever want to. The work of iPhone hackers is appreciated even by those who've never felt the jailbreak itch.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network