[27758] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Yahoo Messenger: Invisible User Detect

daemon@ATHENA.MIT.EDU (Chris Caydes)
Fri Nov 8 03:40:02 2002

Message-ID: <20021107191905.76425.qmail@web13006.mail.yahoo.com>
Date: Thu, 7 Nov 2002 11:19:05 -0800 (PST)
From: Chris Caydes <chris_caydes@yahoo.com>
To: bugtraq@securityfocus.com
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii

Hello,

I have seen this bug a few months ago and have been
using it every now and then since.

Yet, if the user is online in invisible mode and you
ask for his shared files, he will likely get a pop-up
telling him that someone is trying to access his
files. This probably depends on his security
preferences. 

So yes the "exploit" works, but you might be letting
know your "victim" that you're after him.

Chris

== Original Message ==

Exploit:

When you try to access another user's shared files,
you will get a pop-up with a message that either reads
"Asking for permissions" or "user offline".
Even if the user is marked Invisible, you will still
recieve a message confirming that the user is online
and is being asked to allow you permissions. So even
when your friends look like they are offline, right
click on thier name and select "View Shared Files" to
find out for sure!

- cringe


__________________________________________________
Do you Yahoo!?
U2 on LAUNCH - Exclusive greatest hits videos
http://launch.yahoo.com/u2

home help back first fref pref prev next nref lref last post