Yahoo! Messenger Invisible User Detection Weakness
BID:6121
Info
Yahoo! Messenger Invisible User Detection Weakness
| Bugtraq ID: | 6121 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2002 12:00AM |
| Updated: | Nov 07 2002 12:00AM |
| Credit: | Discovery credited to cringe <[email protected]>. |
| Vulnerable: |
Yahoo! Messenger 5.0 .1232 Yahoo! Messenger 5.0 .1046 |
| Not Vulnerable: | |
Discussion
Yahoo! Messenger Invisible User Detection Weakness
Yahoo! Messenger allows users to set their status to 'Invisible' so that other users are not informed that the user is online. A Yahoo! Instant Messenger user can determine if another user is online by requesting access to the user's shared files.
The message returned by this request will contain information that reveals the user's true online status. Note, however, that the 'Invisible' user will receive a message asking whether to allow the requestor permission to access the file shares.
Yahoo! Messenger allows users to set their status to 'Invisible' so that other users are not informed that the user is online. A Yahoo! Instant Messenger user can determine if another user is online by requesting access to the user's shared files.
The message returned by this request will contain information that reveals the user's true online status. Note, however, that the 'Invisible' user will receive a message asking whether to allow the requestor permission to access the file shares.
Exploit / POC
Yahoo! Messenger Invisible User Detection Weakness
There is no exploit code necessary.
There is no exploit code necessary.
References
Yahoo! Messenger Invisible User Detection Weakness
References:
References:
- Yahoo! Instant Messenger Homepage (Yahoo!)
- Re: Yahoo Messenger: Invisible User Detect (Chris Caydes
) - Yahoo Messenger: Invisible User Detect ("cringe"
)