IM through AOL reveals large hole

hissy

TCS Member
Thread starter
Veteran
Joined
Feb 19, 2001
Messages
34,872
Purraise
77
Security hole found in AOL Instant Messenger
January 2, 2002 Posted: 6:58 PM EST (2358 GMT)




--------------------------------------------------------------------------------





--------------------------------------------------------------------------------

RESTON, Virginia (CNN) -- AOL Time Warner's popular AOL Instant Messenger has a security flaw that could enable a hacker to invade a user's computer and wreak havoc on the system, the company and a security group said Wednesday.

AOL spokesman Andrew Weinstein said there have been no indications that hackers have exploited the flaw, which should be fixed by Thursday or Friday. AOL Time Warner is the parent company of CNN.com

"This is more of a theoretical issue because we don't believe this has actually occurred," Weinstein said. "We have developed a resolution, and it should be deployed in a day or two."

He described the fix as a "server-side resolution" that AOL would repair itself, so "users won't have to do anything" to fix the problem.

The problem has to do with a new feature that allows users to play online games with each other. The security flaw appears only in its most recent Windows version of AIM, 4.7, Weinstein said.

The group that discovered the flaw says it dates back to at least the 4.3 version. The group, w00w00, is a nonprofit security organization that has members in nine countries, including Russia, the United States and Australia.

Non-Windows versions are not affected by the problem.

Until AOL fixes the problem, w00w00 recommends users restrict incoming messages to friends on their "Buddy List." A user can do this by going to "Your Preferences." In the "Privacy" section, click "Allow Only Users on My Buddy List" under "Who Can Contact Me," the security group said.

Not taking such an action would leave the program vulnerable to a worm or virus similar to Melissa, ILOVEYOU and Code Red, which have caused problems in computers worldwide.

The flaw is "relatively simple to exploit."

"The implications of this vulnerability are huge and leave the door wide open for a worm," w00w00 said in a statement on its Web site. "This vulnerability will allow remote penetration of the victim's system without any indication as to who performed the attack. There is no opportunity to refuse the request."

AIM has more than 100 million users on its various versions.
 

deb25

TCS Member
Top Cat
Joined
Feb 6, 2001
Messages
12,773
Purraise
6
According to the bottom line on CNN, the problem has been corrected.
 

donna

TCS Member
Top Cat
Joined
Jan 2, 2001
Messages
1,588
Purraise
6
Here's another AOL glitch...my best friend's boyfriend has aol and his phone bills were running $200. It seems that whenever he went on-line, AOL would dial up what showed as a local number. But...it was actually dialing up a toll number. He didn't find out about it till he got his phone bills. He's now fighting with AOL and the phone company. The phone company said there's nothing they can do and he's responsible for the bills. AOL is checking into it, but denying it's their fault. I'm so glad I have USA Datanet. It's $16.95 a month for unlimited use and I've never had a problem signing on. AOL I think has gotten too big for their britches.
 
Top