Home
Strategic Consulting
Professional Services
SOX and SAS-70s
Company Information
Clients
White Papers
News
Contact Us
Events

More Whitepapers  
›  SAS 70 Frequently Asked Questions
›  IT Security Benchmarking – Compare yes, but insist on hard data too.
›  IT Security Awareness in Finance – “ People are the weak link
›  Understanding the Many Benefits of a SAS 70
›  SAS 70 Overview and Planning Guide
›  Polar Cove’s Experience in Sarbanes-Oxley Sec. 404 – A Roadmap
›  Detecting Wireless LAN MAC Address Spoofing


›  Layer 2 Analysis of WLAN Discovery Applications for Intrusion Detection
›  Security Should be part of Business Continuity Planning
›  Securing Your Most Valuable Asset
›  Hack Proofing Your Web Servers
›  MSN Instant Messenger Vulnerability
›  Protecting Against SQL Injections
›  Security is not a Product You Buy

MSN Instant Messenger Vulnerability        [ PDF ]
By Seyha Phul


Instant messaging is a great way for friends and family to communicate in real-time over the internet. It's also a great way for malicious hackers to get control of your computer system, thanks to a vulnerability found in the MSN Chat control.

Microsoft's instant messaging services has a critical vulnerability that can easily be exploited through an e-mail, webpage, or through any other means by which an attacker is able to supply HTML to an Internet Explorer client.

The vulnerability was discovered by Drew Copley, a quality assurance professional at Eeye. Through further investigation, it became apparent that the control contains a buffer-overflow vulnerability. According to Marc Maiffret, Eeye's chief hacking officer, "The attack doesn't happen through the chat client, as long as you have MSN Messenger installed. If I send you a special URL, I can own you."

Fear not this vulnerability. You now have everything you need to protect yourself: knowledge. Now that you know, you can begin to solve the problem. First, ask yourself if this service is necessary. If not, simply remove it from all machines. If it is necessary, you can upgrade to the new version of MSN Messenger. You can get more information and the necessary upgrade patch from Microsoft's security bulletin. After upgrading, the version number of the software should be "4.6.0079". If you are using the Web-based MSN Chat control, the version number should be "2.3.204.3001."

 
Virus Alerts

more »


Contact us
For any questions you may have, contact us at
1-401-454-3939.
Our Polar Cove representative will answer and assist you with your specific needs.

 

[ Back to Top ]

   Privacy Statement    ||    Sitemap    ||    Careers
© 2006     Polar Cove