This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

Do you Yahoo!? Might want to read this....

2 min read

This thread's last reply is from May 20, 2005, 7:46 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

"Yahoo! Chat Add Buddy Without Consent Privacy Issue

Services affected: ALL of Yahoo! Chat
Description: A vulnerability exists in Yahoo!'s Chat servers that allows for chatters to be added to your friends list completely without their knowledge or permissionof the operation. As a result private status messages can be read and online Yahoo! Chat activity can be monitored stealthily."


Security Focus BUGTRAQ here.

And another....

"Yahoo! Messenger URL Handler Remote DoS Vulnerability

Application affected: Yahoo! Messenger ver. 5.x - 6.0 Windows (all builds), *Nix/Mac ? (not tested)
Description: A Denial-of-Service attack can be launched against Yahoo! Messenger which can be exploited both locally and remotely through IFRAMEs or by tricking the target into clicking on a YMSGR: URL handler link when in chat or in pm. A remote user can disconnect Yahoo! Messenger users via e-mail or by having the victim visit a web page."


Security Focus BUGTRAQ here.

:!:
Bump
"Application affected: Yahoo! Messenger ver. 5.x - 6.0 (all builds) Windows, *Nix/Mac ? (not tested)

Description: By activating the "Logfile" feature in Yahoo! Messenger a person (perhaps unauthorized) is able to secretly log and view virtually all communications sent and received by Yahoo! Messenger from all IDs logged into Messenger on the local computer. Awareness of this logging is virtually none unless this feature is exclusively known about beforehand by the users and they know exactly where to look for the feature's presence (not likely). When using this feature you may be susceptible to privacy breaches and increased risk for potential remote DoS attacks to be launched successfully."


Security Focus BUGTRAQ.
"The newly-made available Yahoo! Messenger 7.0 beta build 224 also stores the same information in clear-text as 5.x - 6.0 versions do when the Logfile is enabled (tested on Windows only). Yahoo! Messenger 7.0 was just made available several hours ago in a beta form. Hopefully later builds won't have this 'feature' altogether."

Security Focus BUGTRAQ.
"Security researchers have discovered a denial of service vulnerability involving Yahoo!'s popular instant messaging client. Hackers can potentially disconnect users from chat sessions by sending malformed packets to Yahoo! Messenger servers."

Full story here.