Icq 2001&2002 vulnerability

From: Michael (spacoomat_private)
Date: Wed Jul 24 2002 - 08:38:22 PDT

  • Next message: Demi Sex God from Hell: "Potential remote root in CodeBlue log scanner"

    
     ('binary' encoding is not supported, stored as-is)
    Icq 2001&2002 have feature, that allows to insert graphical smiles.
    I found, that if you send message filled with lots of smiles(icq msg can 
    be about 7000 bytes long), then target icq hangs for 10-20 seconds, 
    consuming all CPU time, or simply crashs.
    
    It seems for me that such type of message crashs only icq's that have 
    large .dat file, which holds all history.
    
    You can download working example from: http://www.iFud.com/dfm/DFMa.exe
    
    As you maybe remember, AOL was trying to threaten me for finding bugs. You 
    can find new threats here: http://www.iFud.com/aol.htm
    
    Michael, icq 102166
    



    This archive was generated by hypermail 2b30 : Wed Jul 24 2002 - 11:46:23 PDT