Author Topic: Trillian 3 Vulnerability  (Read 2323 times)

0 Members and 1 Guest are viewing this topic.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Trillian 3 Vulnerability
« on: August 02, 2005, 09:38:46 am »
Quote
Hi Everyone,

I was playing around with Trillian Pro 3.1 Build 121 and noticed a very disturbing behavior when using it to check my yahoo mail.

When you choose the option to check your yahoo email from Trillian (The little connection ball -> Check Yahoo Mail) it creates a temp file in the <Install Directory>\users\default\cache with a random name that contains the yahoo password in *clear text* and this file is world readable. This would be somewhat ok if the file was deleted as soon as the login was done but the file just sits there till you exit out of trillian. Logging out doesn't erase the file. I have watched the file exist on my system for over two weeks.

Now I shouldn't have to tell you why having a file like this will a password in clear text is such a bad idea. All anyone needs is 2 mins unsupervised on a computer that uses trillian and they will have the user's password and since a lot of people use the same password for various sites this will compromise a lot of other accounts too.

In my opinion the file shouldn't contain the password in the first place but even if it *has* to have the password it should be deleted as soon as the login is done and not sit there for over two weeks.

I have duplicated this with Trillian 3.0 Basic and Pro also. Tested on Windows XP Pro and Windows 2000.

I have attempted to contact Cerulean Studios multiple times before releasing this using their webform, email and forums over the past month but havn't heard anything back from them. My last attempt to contact them was on 06/13/2005. Since I havn't heard anything from them I am sending this to Bugtraq.

If you have any questions/comments about this let me know.

Thanks,
 Suramya

--
----------------------------------------------------------
Mountain Dew and doughnuts... because breakfast is the
most important meal of the day
----------------------------------------------------------
Name : Suramya Tomar
Homepage URL: http://www.suramya.com
-------------------------------------------------

************************************************************
Disclaimer:
Any errors in spelling, tact, or fact are transmission errors.
************************************************************

Offline Quik

  • Webmaster Guy
  • x86
  • Hero Member
  • *****
  • Posts: 3262
  • \x51 \x75 \x69 \x6B \x5B \x78 \x38 \x36 \x5D
    • View Profile
Re: Trillian 3 Vulnerability
« Reply #1 on: August 02, 2005, 03:21:26 pm »
I saw this yesterday but could not replicate it.
Quote
[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Trillian 3 Vulnerability
« Reply #2 on: August 04, 2005, 04:48:08 pm »
I saw this yesterday but could not replicate it.

Did you follow the instructions?

Quote
When you choose the option to check your yahoo email from Trillian (The little connection ball -> Check Yahoo Mail) it creates a temp file in the <Install Directory>\users\default\cache with a random name that contains the yahoo password in *clear text* and this file is world readable.

The key that a lot of people miss is that you have to check your Yahoo mail. 

Offline Quik

  • Webmaster Guy
  • x86
  • Hero Member
  • *****
  • Posts: 3262
  • \x51 \x75 \x69 \x6B \x5B \x78 \x38 \x36 \x5D
    • View Profile
Re: Trillian 3 Vulnerability
« Reply #3 on: August 04, 2005, 05:52:28 pm »
I use the program to check my own mail. I have not been able to find a file that contains text.
Quote
[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny