RE: Trillian Remote DoS Attack - AIM

From: Joshua Wright (Joshua.Wrightat_private)
Date: Tue Sep 24 2002 - 05:43:18 PDT

  • Next message: Ulf H{rnhammar: "[Full-Disclosure] Re: Apache 2.0.(39|40) DOS (PHP!)"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    I was unable to reproduce a Trillian crash in this manner.
    
    Using Trillian 0.74b on Windows XP sp1, test client Windows 2000 sp2
    using AOL IM 5.0.2938.
    
    Sent strings "P > O < C", "ee > 3e < 3dsaf", "3 > 3 < 3", "computer >
    security < now" using a variety of fonts in AOL IM.  Did not see a
    significant jump in CPU or memory utilization.
    
    - -Joshua Wright
    Team Leader, Networks and Systems
    Johnson & Wales University
    Joshua.Wrightat_private 
    
    pgpkey: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xD44B4A73
    fingerprint: FDA5 12FC F391 3740 E0AE BDB6 8FE2 FC0A D44B 4A73
    
    
    
    > Impact
    > Trillian crashes and you have to restart. Bonus is if you
    > keep crashing the person, AIM services will ban them for
    > login flooding (Timed Ban).
    
    
    > #########################
    > # Offending Data String #
    > #########################
    > Send a AOL IM to someone with this string anywhere in the message
    > (the spaces must be there)
    > 
    > P > O < C
    > 
    > And it will cause the application to crash. Other data 
    > strings do work IE
    > ee > 3e < 3dsaf 
    > 3 > 3 < 3
    > computer > security < now
    > 
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>
    
    iQA/AwUBPZBd5o/i/ArUS0pzEQK2KwCePKyvZfvNAiCnhzlAWgsuCsDiGkEAoPs7
    oWbp8KSm0iK89qcb+xc3Vg7w
    =DdUp
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Tue Sep 24 2002 - 10:56:12 PDT