Mar 27 2005

Security Flaw Found In Trillian IM Client

  • Written by
  • No Comments


The popular Trillian instant-messaging client contains a security flaw that could allow a hacker to gain control of a person’s computer, a software company said Friday.

To take advantage of the vulnerability, the hacker would have to use an advanced technique called DNS cache poisoning, which redirects PC users from real sites to spoofed copies, said Matt Hargett, director of development for Pittspurgh, Pa.-based, LogicLibrary Inc. The tactic involves a hacker first compromising a DNS server, which is used on the web to direct computers to websites.

Once Trillian, which is made by Cerulean Studios in Connecticut, is directed to a spoofed server, a hacker could upload malware by overflowing the software’s buffer, or temporary storage area, with data containing executable code. Overflowing the buffer fools the software into running the code.

The damage to an infected PC could range from an annoying program crash to a hacker gaining control of the machine, Hargett said. Such an attack is particularly nasty because the user is unaware that his computer is being hijacked.


Read the complete story @ TechWeb News

Related

  1. MSN Messenger network to kick off third party applications (as Trillian) by Oct. 15.
  2. A Browser Flaw a Day Keeps Hackers at Play
  3. Kazaa Security Flaw
  4. Firefox a “complete security mess”
  5. Ex-Microsoft Security Strategist Joins Mozilla
Zeropaid on Facebook

Trackbacks url:

Leave a Comment...



  • Advertisement

    Giganews Newsgroups


  • RJH: The US government will cease to exist before file sharing does. I would bet anything on that....
  • dave: fucking hypocrite. Supposedly standing up for human rights all over the world but wants to adopt totalitarian Internet c...
  • Pirate Home Page » IFPI Claims “3-Strikes” Can Remove Single User, Not Household: [...] Spokesperson also tells audience at the Congressional Internet Caucus’ State of the Net conference that ther...
  • Pirate Home Page » ACTA Falling Apart?: [...] ACTA has been called many things over the years since it was first leaked online, but an all around failure was ce...
  • Niklas Starow: Manual pingback http://dnmr.blogg.se/2010/february/acta-falling-apart-thanks-to-internet-activis.html...
  • @collentine: Interesting but might as well be the opposite with all the secrecy surrounding it....
  • Prove It: Since when has anyone believed the MPAA or RIAA to promote open transparency? This article doesn't submit any FACTS,...
  • chickmagnet 43: awesomer...
  • sdsd