Toon posts:

Exploit in MSN Messener 6.1.0207

Pagina: 1
Acties:
  • 42 views sinds 30-01-2008

Verwijderd

Topicstarter
Er is een grote fout gevonden in MSN Messenger 6.1.0207. Het heeft te maken met het bestand versturen via MSN. Ondertussen is msn al geupated naar versie 6.1.0211 en in die versie is het probleem al verholpen. Maar veel mensen gebruiken nog de versie 6.1.0207 :|
Technical description:

A security vulnerability exists in Microsoft MSN Messenger. The vulnerability exists because of the method used by MSN Messenger to handle a file request. An attacker could exploit this vulnerability by sending a specially crafted request to a user running MSN Messenger. If exploited successfully, the attacker could view the contents of a file on the hard drive without the user's knowledge as long as the attacker knew the location of the file and the user had read access to the file.

To exploit this vulnerability, an attacker would have to know the sign-on name of the MSN Messenger user in order to send the request.

Mitigating factors:

• An attacker must know the sign-on name of the user
• If the user has blocked receiving messages from anonymous users not on their contact list by placing "All Others" in their block list, the attacker's messenger account must be on the user's allow list to exploit the vulnerability.
• The attacker could access files that the user had read access to. If the user is logged into the computer with restricted privileges this would limit the files that the attacker could access.
Bron: http://62.212.87.198/?msn=news&id=226#comment

Verwijderd

Topicstarter
oke mijn fout! >:) dacht dat dit nog niet bekend was.

  • momania
  • Registratie: Mei 2000
  • Laatst online: 22:44

momania

iPhone 30! Bam!

:z

Neem je whisky mee, is het te weinig... *zucht*


Dit topic is gesloten.