Welcome | Sign In
ECommerceTimes.com
Security

Webcam Chats With Strangers Could Trigger Yahoo Messenger Attack

Print Version
E-Mail Article
Reprints
Webcam Chats With Strangers Could Trigger Yahoo Messenger Attack

McAfee's Avert Labs has called out a zero-day trick that could be used by hackers to attack users of Yahoo Messenger. While a fix isn't ready at this time, end users can easily avoid the problem if they don't accept webcam invites from untrusted sources. The threat is the latest in a growing trend of IM-based attack vectors.


Success is just a matter of knowing the right "secrets." Download the free eBook, "The Edge of Success: 9 Building Blocks to Double Your Sales." You will discover the fastest, most effective ways to grow your business and still have time to live your life.

McAfee has confirmed a zero-day vulnerability in Yahoo's (Nasdaq: YHOO) popular instant messaging solution, Yahoo Messenger. McAfee's Avert Labs is a security research firm designed to tackle security issues as soon as they trickle into the world, and the crew first noticed the potential flaw on a post on a Chinese-language security forum.

The flaws, according to McAfee, allows for a user-assisted remote code execution attack, meaning an IM user has to act in response to a prompt from a hacker in order for the attack to proceed.

McAfee Avert Labs reproduced the vulnerability on Yahoo Messenger version 8.1.0.413.

Piling On the Heap

"It seems like a classic heap overflow, which can be triggered when the victim accepts a webcam invite," explained Avert Labs' Wei Wang. "Note that this vulnerability is different from the recently patched one in June, which exploited the Yahoo Webcam ActiveX controls."

McAfee has alerted Yahoo of the issue, the research firm said. Yahoo posted a fix of the webcam ActiveX in June. While a fix isn't ready at this time, end users can easily avoid the problem if they don't accept webcam invites from untrusted sources.

For its part, McAfee has also released its network intrusion protection system IntruShield signatures, which protect Yahoo Messenger users from the threat.

Growing IM Issues?

Yahoo Messenger was the victim of the above-mentioned webcam ActiveX attack earlier this year, but have there been many others?

"Prior to 2002, 2003, there were only a couple dozen IM-based threats in total, but now sometimes we see upwards of 70 or 80 new ones a month," Dave Marcus, security research and communications manager for McAfee Avert Labs, told TechNewsWorld.

"It's definitely been a growing area for a couple of years, which really makes sense when you consider how many more people now are using IM as a communication tool than in past years," he added.

IM Vigilance

What's the best way to avoid IM-based vulnerabilities?

"Some of the same best practices with basic e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse safety transition to IM, too," Marcus said.

"You've got to be careful of people sending you stuff who are not on your buddy list. A lot of [nefarious] people like to send links that are not correct, that are fake links to sites with malware, spyware or trojans," he explained. "Not accepting messages from people outside of your buddy list is a first place to start."

Despite this, there are a lot of tools in the underground that let hackers capture IM traffic between parties, which could also help them try to fake the identity of someone an IM user is friends with. To make matters worse, there's a growing trend of hackers using malware to steal identities and glean personal information for profit.

For even stronger protection, Avert Labs recommends that people block outgoing traffic on TCP port 5100 until Yahoo patches the vulnerability.


Print Version E-Mail Article Reprints More by Chris Maxcer


More by Chris Maxcer

Let's Give the iPhone Hackers a Big Round of Applause
November 06, 2009
It's safe to say most Apple customers are satisfied living in the walled-off ecosystem that the company has created for products like the iPhone. Still, it's good to know that it is possible -- and relatively easy, even -- to bust through those walls if one should ever want to. The work of iPhone hackers is appreciated even by those who've never felt the jailbreak itch.
What the iPhone Needs to Keep the Android Hordes at Bay
October 30, 2009
The Android platform is growing fast, and Verizon is readying what may be the best Android phone yet. Consumers are getting more Android options on more networks. Meanwhile, Apple is sticking to a consistent device design on a single network. The iPhone doesn't need to branch off into multiple sizes and styles to be the dominant platform, but its single-U.S.-carrier situation is another story.
Apple Is Saving the Best for Last
October 23, 2009
Sifting through the language used in Apple's quarterly results conference calls can sometimes yield clues to the highly secretive company's next moves. Apple's latest phone chat with analysts included a few comments about December shipping costs and a mystery "product." Here's why we might see an Apple tablet before the new year.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network