News:

Facebook killed the radio star. And by radio star, I mean the premise of distributed forums around the internet. And that got got by Instagram/SnapChat. And that got got by TikTok. Where the fuck is the internet we once knew?

Main Menu

WARNING to Trillian3 users!

Started by iago, March 08, 2005, 10:52:47 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

iago

Quote##################################################################
#                                                                #
#               See-security Technologies ltd.                   #
#                                                                #
#                http://www.see-security.com                     #
#                                                                #
##################################################################

[-] Product Information
Trillian is a fully featured, stand-alone, skinnable chat client that supports AIM, ICQ, MSN, Yahoo Messenger, and IRC.

[-] Vulnerability Description
Trillian contains a buffer overflow vulnerability in the way it parse PNG Images

[-] Exploit
Proof of concept exploit code is available at http://www.hackingdefined.com/exploits/trillian3.tar.gz

[-] Exploitation Analysis
When triggering this vulnerability the return address is overwritten
and the ESP register points to user-controlled data
by crafting a malformed structure its possible to execute arbitrary code
The structrue is as follows
[Malformed PNG Header][shellcode][New return address][get back shellcode]

[-] Credits
The vulnerability was discovered and exploited by Tal zeltzer

There's a vulnerability and exploit code for it! Watch out!

Joe

Quote from: Camel on June 09, 2009, 04:12:23 PMI'd personally do as Joe suggests

Quote from: AntiVirus on October 19, 2010, 02:36:52 PM
You might be right about that, Joe.


Quik

There's been so many Trillian buffer overflow exploits that it's really not worth looking into anymore. You can drop the thing with like 5 lines of Perl code, or a few different ways with GAIM plugins. For this one, I'm assuming you have to directly connect, because otherwise there's not much of a way it can parse PNG images. Just connect to people you trust, is all.
Quote[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny

iago

I'm unsure if you can send a .png as a buddy icon, but if you can then that could be quite dangerous.

And judging by Trillian's track record, you can expect a fix in a few years :)

Towelie

maybe another 5, they are really fast....