|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: May 2002
Posts: 105
|
ICQ hack, watch out
Got this today:
"I have created an example exploit on http://www.xs4all.nl/~jkuperus/icq/icq.htm that starts a little flame program It works as followed the default action for icq soundscheme (scm) files is open it places the wav files included with the scm file in a known location on the hard disk. flame.scm wil be downloaded and installed in C:\Program Files\ICQ\Sounds\flame[1] the scm file i use creates a auth.wav file . In reality however this is not a wav file but a mht (mail archive file) with en embeded base64 encoded executable then i use one of the many available local code execution vulnerabilities found in internet explorer recently to execute the embedded binary with this url : mhtml:file:///C:/Program%20Files/ICQ/Sounds/flame/Auth.wav!file:///C:/fire.exe I dont think its necisary to use one of ie's exploit as you can also call html files in the mht archive, But for some reason i wasn't able to get this to work right away. >>Workaround << For a short term solution open explorer (the file manager not the browser) go to the file types tab in tools > folder options locate the scm extention and change the default behaviour to prompt before download In the long term icq will have to use something like random foldernames for soundschemes to prefent this from happening" |
|
|
|
|
|
#2 |
|
Confirmed User
Industry Role:
Join Date: Aug 2001
Posts: 8,855
|
Now this is usefull info!!!
That's why I like this board!!! |
|
|
|
|
|
#3 |
|
Confirmed User
Join Date: Jun 2002
Posts: 1,103
|
thats scary... thats why i dont use icq anymore.. its unsafe and users with icq can get hacked
|
|
|
|
|
|
#4 |
|
Confirmed User
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
|
Feel free to call me stupid, but...
C:/Program%20Files/ICQ/Sounds/flame/Auth.wav I found this, now what is it we need to do to prevent what?
__________________
seks.ai for sale - ping me |
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Feb 2001
Posts: 1,917
|
THIS IS FUCKING UNREAL!!
I cannot believe ICQ does this... it shocked the hell outta me, since I thought that URL was a page that was going to explain the hack in more detail... WOW! This should be posted in a forum or thread where everyone can read it... to make sure everyone can read it. |
|
|
|
|
|
#6 |
|
Master of Gfy.com
Industry Role:
Join Date: Feb 2002
Posts: 14,887
|
I hope
cheatski.com doesnt find out about this ![]() |
|
|
|
|
|
#7 |
|
Confirmed User
Join Date: Feb 2001
Posts: 1,917
|
I found that just deleting the sounds directory prevents this. I never use the sounds anyway, so I already had them turned off before I did this. ICQ doesn't seem to mind.
|
|
|
|
|
|
#8 |
|
So Fucking Banned
Join Date: Sep 2001
Location: shell beach
Posts: 7,938
|
we will see this on millions of gallery pages soon. hint, if you tweek the script a little you can autoinstall dialers and shit, and ICQ is not really necessary to get it working ...
thanks for posting,idiot, twat, pissnelke !!! |
|
|
|
|
|
#9 | |
|
Confirmed User
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
|
Quote:
How is this done?
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a> Tons of Hosted Galleries. |
|
|
|
|
|
|
#10 | |
|
Confirmed User
Industry Role:
Join Date: Jan 2002
Location: AdultWebmasterInfo
Posts: 2,353
|
Quote:
does that apply to all versions of icq ? if someone can help me out icq me please #121258311 |
|
|
|
|
|
|
#11 | |
|
Master of Gfy.com
Industry Role:
Join Date: Feb 2002
Posts: 14,887
|
Quote:
|
|
|
|
|
|
|
#12 |
|
Confirmed User
Industry Role:
Join Date: Aug 2001
Posts: 784
|
__________________
I'm back and happy about it. |
|
|
|
|
|
#13 |
|
Confirmed User
Join Date: Feb 2002
Location: LA
Posts: 1,058
|
thats crazy, i am practically computer illeterate, and even I can figure out how to fuck with someones computer with a program like that...scary shit.
|
|
|
|
|
|
#14 |
|
rockin tha trailerpark
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
|
__________________
__________ Loadedca$h - get sum! - Revengebucks - mmm rebills! - webair (gotz sErVrz)
|
|
|
|
|
|
#15 |
|
Confirmed User
Join Date: Feb 2001
Posts: 1,917
|
I don't know if my method of deleting the 'sounds' directory works for all versions of ICQ or not. All I know is that the program cannot be run, if the html file is looking for it in a directory that does not exist. So, yes, it will prevent this no matter which ICQ version you use. BUT I CANNOT GAURANTEE that it will not fuck up your ICQ. So make sure you can restore the directory if it doesn't work. (I hate those ICQ sounds, anyway, so I have them turned off.)
Also, realize that this can probably be done in other programs that auto download and install (WHY THE FUCK does windows allow this to happen? We are supposed to be able to tell windows to download or run from location for each file it downloads through IE). Winamp does this with plugins, so the same thing would be possible if the plugins go to the same directory every time. ALSO REALIZE that these programs do not have to contain viruses that can be detected by your virus scanner. They can very well contain new viruses OR THEY COULD SIMPLY CONTAIN A PROGRAM THAT DELTREES YOUR ENTIRE SYSTEM. Virus scanners would not catch this, as it is not a virus, and does not attempt to hide itself or recreate itself. This is too fucking crazy, and makes me mad |
|
|
|
|
|
#16 | |
|
Confirmed User
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
|
Quote:
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a> Tons of Hosted Galleries. |
|
|
|
|
|
|
#17 |
|
OG
Industry Role:
Join Date: Dec 2001
Location: 3rd from the Sun
Posts: 13,236
|
Neither Funbrunette or I have been able to log on to ICQ today...
I hope this isn't the reason why....
__________________
|
|
|
|
|
|
#18 |
|
Confirmed User
Join Date: May 2002
Location: the box
Posts: 456
|
Anyone ever try the icq alternatives? Like SecureICQ?
Take a look: http://download.com.com/3120-2001-0-...re+icq&ca=2001 |
|
|
|
|
|
#19 |
|
Confirmed User
Join Date: May 2002
Location: CT
Posts: 5,246
|
Trillian
|
|
|
|
|
|
#20 | |
|
Confirmed User
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
|
Quote:
Tell me how to fix that too if you please, this wasn't a funny thread ![]() |
|
|
|
|
|
|
#21 |
|
Confirmed User
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
|
Fuck it, I got it
|
|
|
|
|
|
#22 | |
|
Confirmed User
Join Date: Feb 2001
Posts: 1,917
|
Quote:
|
|
|
|
|
|
|
#23 |
|
Confirmed User
Join Date: Jan 2001
Posts: 3,539
|
Didn't work on my system.
Is that because I have ICQ sounds turned off or because I have Windows XP or ...? |
|
|
|
|
|
#24 |
|
OU812
Join Date: Feb 2001
Location: California
Posts: 12,651
|
I should not have any problem...as I have ICQ installed on my D: drive. but am going to check anyway.
__________________
Epic CashEpic Cash works for me Solar Cash Paysite Plugin Gallery of the day freesites,POTD,Gallery generator with free hosting |
|
|
|
|
|
#25 | |
|
Confirmed User
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
|
Quote:
to the next action DynaMite
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho | |
|
|
|
|
|
|
#26 | |
|
OU812
Join Date: Feb 2001
Location: California
Posts: 12,651
|
Quote:
__________________
Epic CashEpic Cash works for me Solar Cash Paysite Plugin Gallery of the day freesites,POTD,Gallery generator with free hosting |
|
|
|
|
|
|
#27 |
|
Confirmed User
Join Date: Mar 2002
Location: Ft Worth TX
Posts: 291
|
As long as your running a firewall, and dont have the firewall set to let programs automatically do shit like that, your FINE!
__________________
Loved By Some, Hated By Most.... <a href="http://www.unclejimsporn.com">http://www.unclejimsporn.com</a> <a href="http://www.cousindirty.com">http://www.cousindirty.com</a> <a href="http://www.drunkspringbreakchics.com">http://www.drunkspringbreakchics.com</a> |
|
|
|
|
|
#28 |
|
Confirmed User
Join Date: Feb 2001
Posts: 1,917
|
I have a firewall, but it didn't block this program from being run, according to the default settings.
It didn't stop it from downloading the files since it has given ICQ the right to download sound themes (the .exe was hidden in a sound themes file). And then the html runs the hidden file (somehow - I didn't really look to see what was going on) from your own computer... I am not sure why it let this happen, but I do know that a lot of programs are run on your own computer without your permission... Has anyone analyzed the file, yet? |
|
|
|
|
|
#29 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
good catch!
|
|
|
|