[27175] in bugtraq
RE: Trillian Remote DoS Attack - AIM
daemon@ATHENA.MIT.EDU (Eric Stevens)
Tue Sep 24 16:36:36 2002
From: "Eric Stevens" <mightye@mightye.org>
To: "Bugtraq" <bugtraq@securityfocus.com>
Date: Tue, 24 Sep 2002 13:38:11 -0400
Message-ID: <LKECKOOCIJJCLJLDDELLEEBFCFAA.mightye@mightye.org>
MIME-Version: 1.0
Content-Type: text/plain;
charset="US-ASCII"
Content-Transfer-Encoding: 7bit
Tried unsuccessfully to replicate on Trillian 0.73, sending from Trillian
Pro 1.0. Sent
P > O < C
by itself. Sent during both encrypted, and non-encrypted sessions. No
crash reported on either end.
-MightyE
-----Original Trimmed Message-----
From: Spikeman [mailto:spikeman@computersecuritynow.com]
Subject: Trillian Remote DoS Attack - AIM
#########################
# Offending Data String #
#########################
Send a AOL IM to someone with this string anywhere in the message
(the spaces must be there)
P > O < C
And it will cause the application to crash. Other data strings do work IE
ee > 3e < 3dsaf
3 > 3 < 3
computer > security < now