Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Android, Apple Own 80% of Global Smartphone Market; Microsoft's Share, 2.2%
Proposed New York Legislation Would Ban Anonymous Online Comments
Supercomputer to connect to 400PB of storage via Ethernet
Sales of unused IPv4 addresses gathering steam
Customizable cloud SLAs on the way, researchers predict
Google chairman pledges to fund Raspberry Pi availability in U.K. schools
Obama orders agencies to optimize Web content for mobile
Are CEOs getting the social media thing?
Managing Mobile Mania
Google's Android did not infringe Oracle patents, jury finds
HP to trim 27,000 jobs as part of restructuring program
VMware acquires desktop management company Wanova
Privacy advocates fear CISPA
Groups launch gigabit-per-second broadband project
Windows 8 touchscreen devices to be priced higher, Dell says
/

Security company confirms accusations of a bug in AOL messaging software

Today's breaking news
Send to a friendFeedback

InfoWorld, 08/20/99

The battle between Microsoft and America Online over access to the latter's instant messaging system took a new turn Thursday, after an independent intrusion-detection and security company confirmed Microsoft accusations of a bug in AOL's code.

Network ICE has uncovered a buffer overflow bug within the latest coding of AOL Instant Messaging servers that would enable the systems to identify and block Microsoft users. Network ICE develops intrusion-detection applications to identify hacking attempts, including buffer overflow attacks.

"We logged into an AOL server using an AOL Messenger and did a capture of the traffic between a server and a client. During the log-in process I found what indeed was a buffer overflow exploit," said Robert Graham, Network ICE's chief technical officer. "We make a product that detects buffer overflow exploits, so we were looking into it anyway."

The bug does not attack Microsoft clients attempting to gain access to AOL Instant Messaging servers, but instead affects AOL clients. When an AOL client logs onto an Instant Messaging server, the client will actually send back too much information-like a buffer overflow exploit-therefore identifying Microsoft Messaging clients that do not send back this information excess.

"When an AOL client connects, [it] sends back more information than [the server] expects. The bug is in the AOL client, which is interesting," Graham said. "The buffer that they reserved was 256 bytes. For that buffer, what [the AOL client] sends is 256 bytes and then 24 bytes extra. They send 24 extra to overflow it."

The change of the AOL Instant Messaging server code to include the exploit is the latest in a series of attempts to keep Microsoft instant messaging systems out of the AOL domain.

Network ICE insists that it does not want to take sides between the two industry giants, but that it intends to protect its users from the AOL exploit being used surreptitiously by hackers. A hacker, according to Graham, could masquerade as the AOL exploit to gain access to systems.

"A hacker could interpose themselves between the AOL server and the client and then change the AOL overflow," Graham said. "My goal is not to say anything in the battle between Microsoft and AOL. My goal is to analyze what is going on on the wire."

Network ICE's BlackICE intrusion-detection application has been updated to allow for the AOL exploit, but to monitor for alterations to the original code, which might give away a hacker, according to Graham.

InfoWorld This story from Infoworld.com Copyright © 1999 InfoWorld Media Group, Inc.


RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.