Social engineering - MSN Messenger - Yahoo Messenger - for users this summer it gets worse …

Messaging is being used ever more often at work as well as at home to communicate with friends, associates and strangers. But what about the security?

Well, maybe if you use MSN Messenger, you should try this during a chat session. Ask your buddy to allow you to send her a file. During this process one uses the netstat -an command. This command tells the user the address the file is being transferred to. This works if your buddy is not using a proxy. The command required is exedcuted as follows:

  1. click on start ==> then click on run ==> thereafter type: cmd.exe
  2. at the command prompt type: netstat -an

The above method works for MSN Messenger. If you want the IP of a user on Yahoo Messenger, all you do is add a user to your list with social engineering techniques, then you listen on port 5101 and send the victim a normal instant message. Yahoo compromises security in that way by attempting to establish a peer to peer connection between consumer clients, to save on server useage. Yahoo does not appear to care how easy it is to obtain a users IP by simply sending someone an instant message. Yahoo claims that the fact you need to add each other to a friends list first is good enough security to protect users.

So what good does this do?

Getting a person on your messenger list and sending them an attachment or file via the network will allow you to get their IP address. Even corporate users are rarely behind a proxy. If you want a non-proxy IP from a corporate user, messenger is the application they very rarely use with their corporate proxy.

Is this a security threat?

By adding an individual to one’s messenger buddy list, a potential attacker has (see above command) obtained the IP address of a major dot-com. A hacker can target several machines at your firm’s ends or ISP with this information. Yahoo Messenger at no time alerts its users, ‘do you want to p2p message with this buddy?’.
Instead this just secretly happens in the background. Only technical users are aware of this vulnerability.
Having a non-proxy IP address from a major corporate is great for a hacker that wants to explore things or use a botnet.
Conclusion

For quite some time, the Yahoo messenger protocol has been easy as chips to hack, to obtain cookies, disconnect users from the network etc.

This summer, however, Microsoft Messenger and Yahoo Messenger are about to link their networks giving users across network compatability.

What makes it also worse is that some companies, such as Yahoo backyard host names, all have the corporate ID of the person who uses the computer on their hostname. For instance, Yahoo uses:

  • corpid.corp.yahoo.com

As a result the potentially malicious user knows

  1. the corporate login of the user,
  2. the real name of the user and
  3. the corporate e-mail of the user

Most certainly, Yahoo is not the only enterprise doing this is it?

=======>

PS1. You need a direct connection to the Internet to use the netstat trick: accordingly, DSL modem or a dialup modem that gives your machine the WAN IP - then this will work.

PS2. Jeremy Zawodny’s blog continues to have juicy stuff about Yahoo and MS Messenger as well as Trillian software (too bad I cannot get his postings via e-mail for convenience’s sake).

=======>

_EFFICIENCY

Since 2000 we have been providing alerts, tips, tricks, white papers and legal briefs for people like yourself. Why not save yourself some time, provide us with your e-mail address and get better information sent to your in-box in upcoming weeks?

Your email:  
subscribe unsubscribe  

Technorati , , , , , , , , ,

WordPress database error: [Can't find file: './Blog/wp_post2cat.frm' (errno: 13)]
SELECT post_id, category_id FROM wp_post2cat WHERE post_id IN (29)

Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

WordPress database error: [Table './Blog/wp_comments' is marked as crashed and last (automatic?) repair failed]
SELECT * FROM wp_comments WHERE comment_post_ID = '29' AND comment_approved = '1' ORDER BY comment_date

Leave a Reply

WordPress database error: [Table './Blog/wp_comments' is marked as crashed and last (automatic?) repair failed]
DESC wp_comments


Warning: Invalid argument supplied for foreach() in /var/www/hosts/cases/blog/wp-content/plugins/subscribe-to-comments.php on line 676

WordPress database error: [Table './Blog/wp_comments' is marked as crashed and last (automatic?) repair failed]
ALTER TABLE wp_comments ADD COLUMN comment_subscribe enum('Y','N') NOT NULL default 'N'

WP-Hashcash: protecting you from spam.