AOL Instant Messenger Password Encryption Weakness
BID:6777
Info
AOL Instant Messenger Password Encryption Weakness
| Bugtraq ID: | 6777 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 1998 12:00AM |
| Updated: | Jun 21 1998 12:00AM |
| Credit: | Discovery of this weakness is credited to James<[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 1.2 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Password Encryption Weakness
It has been reported that AOL Instant Messenger uses a weak method of encryption
while negotiating its sign on process.
The first FLAP packets sent to the OSCAR logon server contain the user login password and screen name which are encrypted using a weak XOR method that is trivial to decrypt.
It has been reported that AOL Instant Messenger uses a weak method of encryption
while negotiating its sign on process.
The first FLAP packets sent to the OSCAR logon server contain the user login password and screen name which are encrypted using a weak XOR method that is trivial to decrypt.
Exploit / POC
AOL Instant Messenger Password Encryption Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AOL Instant Messenger Password Encryption Weakness
Solution:
It is advised that AOL Instant Messenger software is updated to latest version available at the vendor's website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is advised that AOL Instant Messenger software is updated to latest version available at the vendor's website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Password Encryption Weakness
References:
References: