Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-17-2002, 06:57 AM   #1
Rocco Strange
Confirmed User
 
Join Date: May 2002
Posts: 105
ICQ hack, watch out

Got this today:

"I have created an example exploit on

http://www.xs4all.nl/~jkuperus/icq/icq.htm

that starts a little flame program

It works as followed

the default action for icq soundscheme (scm) files is open it places the wav files included with the scm file in a known location on the hard disk.

flame.scm wil be downloaded and installed in C:\Program Files\ICQ\Sounds\flame[1] the scm file i use creates a auth.wav file .

In reality however this is not a wav file but a mht (mail archive file) with en embeded base64 encoded executable

then i use one of the many available local code execution vulnerabilities found in internet explorer recently to execute the embedded binary with this url :

mhtml:file:///C:/Program%20Files/ICQ/Sounds/flame/Auth.wav!file:///C:/fire.exe

I dont think its necisary to use one of ie's exploit as you can also call html files in the mht archive, But for some reason i wasn't able to get this to work right away.


>>Workaround <<

For a short term solution

open explorer (the file manager not the browser)
go to the file types tab in tools > folder options

locate the scm extention and change the default behaviour to prompt before download

In the long term icq will have to use something like random foldernames for soundschemes to prefent this from happening"
Rocco Strange is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 07:45 AM   #2
NickB.
Confirmed User
 
Industry Role:
Join Date: Aug 2001
Posts: 8,855
Now this is usefull info!!!
That's why I like this board!!!

NickB. is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 07:46 AM   #3
RW316
Confirmed User
 
Join Date: Jun 2002
Posts: 1,103
thats scary... thats why i dont use icq anymore.. its unsafe and users with icq can get hacked
RW316 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 07:53 AM   #4
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
Feel free to call me stupid, but...
C:/Program%20Files/ICQ/Sounds/flame/Auth.wav
I found this, now what is it we need to do to prevent what?
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:07 AM   #5
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917

THIS IS FUCKING UNREAL!!

I cannot believe ICQ does this... it shocked the hell outta me, since I thought that URL was a page that was going to explain the hack in more detail...

WOW!

This should be posted in a forum or thread where everyone can read it... to make sure everyone can read it.
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:16 AM   #6
Pipecrew
Master of Gfy.com
 
Pipecrew's Avatar
 
Industry Role:
Join Date: Feb 2002
Posts: 14,887
I hope

cheatski.com doesnt find out about this
Pipecrew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:22 AM   #7
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917

I found that just deleting the sounds directory prevents this. I never use the sounds anyway, so I already had them turned off before I did this. ICQ doesn't seem to mind.
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:26 AM   #8
funkmaster
So Fucking Banned
 
Join Date: Sep 2001
Location: shell beach
Posts: 7,938
we will see this on millions of gallery pages soon. hint, if you tweek the script a little you can autoinstall dialers and shit, and ICQ is not really necessary to get it working ...

thanks for posting,idiot, twat, pissnelke !!!
funkmaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:29 AM   #9
.:Frog:.
Confirmed User
 
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
Quote:
Originally posted by Rocco Strange

locate the scm extention and change the default behaviour to prompt before download
I located the file but didn't see an option to "change the default behaviour to prompt before download"

How is this done?
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a>
Tons of Hosted Galleries.
.:Frog:. is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:44 AM   #10
AWW - Kevin
Confirmed User
 
Industry Role:
Join Date: Jan 2002
Location: AdultWebmasterInfo
Posts: 2,353
Quote:
Originally posted by Juge
I found that just deleting the sounds directory prevents this. I never use the sounds anyway, so I already had them turned off before I did this. ICQ doesn't seem to mind.

does that apply to all versions of icq ?
if someone can help me out
icq me please
#121258311
__________________


Add Your Resource
ICQ: 1212-58311
AWW - Kevin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 08:46 AM   #11
Pipecrew
Master of Gfy.com
 
Pipecrew's Avatar
 
Industry Role:
Join Date: Feb 2002
Posts: 14,887
Quote:
Originally posted by .:Frog:.


I located the file but didn't see an option to "change the default behaviour to prompt before download"

How is this done?
same prob, i just put "confirm after download"
Pipecrew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 09:16 AM   #12
Sex4it
Confirmed User
 
Industry Role:
Join Date: Aug 2001
Posts: 784
__________________
I'm back and happy about it.
Sex4it is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 10:21 AM   #13
roseyrid
Confirmed User
 
Join Date: Feb 2002
Location: LA
Posts: 1,058
thats crazy, i am practically computer illeterate, and even I can figure out how to fuck with someones computer with a program like that...scary shit.
roseyrid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 10:35 AM   #14
pr0
rockin tha trailerpark
 
pr0's Avatar
 
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
Don't use internet explorer.

Use opera www.opera.com
pr0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 10:41 AM   #15
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917
I don't know if my method of deleting the 'sounds' directory works for all versions of ICQ or not. All I know is that the program cannot be run, if the html file is looking for it in a directory that does not exist. So, yes, it will prevent this no matter which ICQ version you use. BUT I CANNOT GAURANTEE that it will not fuck up your ICQ. So make sure you can restore the directory if it doesn't work. (I hate those ICQ sounds, anyway, so I have them turned off.)

Also, realize that this can probably be done in other programs that auto download and install (WHY THE FUCK does windows allow this to happen? We are supposed to be able to tell windows to download or run from location for each file it downloads through IE). Winamp does this with plugins, so the same thing would be possible if the plugins go to the same directory every time.

ALSO REALIZE that these programs do not have to contain viruses that can be detected by your virus scanner. They can very well contain new viruses OR THEY COULD SIMPLY CONTAIN A PROGRAM THAT DELTREES YOUR ENTIRE SYSTEM. Virus scanners would not catch this, as it is not a virus, and does not attempt to hide itself or recreate itself.

This is too fucking crazy, and makes me mad that idiots can allow for such stupid security flaws. Windows, ICQ, winamp, and any other program that sets its file associations to allow for auto download and auto run, are all to blame. All in the effort to make these programs easy for morons to install, because they can't remember where files go when they get downloaded.
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 11:21 AM   #16
.:Frog:.
Confirmed User
 
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
Quote:
Originally posted by Pipecrew


same prob, i just put "confirm after download"
Thats exactly what I selected.
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a>
Tons of Hosted Galleries.
.:Frog:. is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 11:22 AM   #17
Evil Chris
OG
 
Evil Chris's Avatar
 
Industry Role:
Join Date: Dec 2001
Location: 3rd from the Sun
Posts: 13,236
Neither Funbrunette or I have been able to log on to ICQ today...
I hope this isn't the reason why....
__________________


It PAYZE to post on GFY

chris at payze.com | Skype chriswrp
Evil Chris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 06:20 PM   #18
SunTzu
Confirmed User
 
Join Date: May 2002
Location: the box
Posts: 456
Anyone ever try the icq alternatives? Like SecureICQ?

Take a look: http://download.com.com/3120-2001-0-...re+icq&ca=2001
SunTzu is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2002, 06:49 PM   #19
foe
Confirmed User
 
Join Date: May 2002
Location: CT
Posts: 5,246
Trillian
foe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 04:45 AM   #20
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
Quote:
Originally posted by Evil Chris
Neither Funbrunette or I have been able to log on to ICQ today...
I hope this isn't the reason why....
Another thing is that my ICQ sounds don't work anymore now. WTF??

Tell me how to fix that too if you please, this wasn't a funny thread
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 04:47 AM   #21
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,484
Fuck it, I got it
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 06:48 AM   #22
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917
Quote:
Originally posted by Naughty


Another thing is that my ICQ sounds don't work anymore now. WTF??

Tell me how to fix that too if you please, this wasn't a funny thread
I think I know what happened... the webpage automatically downloads the file (which has a hidden .exe in it) because it has it named as a ICQ sounds theme - so ICQ is the culprit automatically downloading and installing this crap (fucking programs no wonder there is so many security leaks, it should have to ASK before downloading AND before installing), anyway, it auto downloads, and then attempts to install it - but it can't install it because it's not an ICQ sounds theme file - it's a text file with a hidden compressed .exe in it that is just renamed to look like an ICQ sounds theme so the stupid insecure ICQ program can download it onto your drive... so now your ICQ's sound theme is set to something invalid. You have to set it back...
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 06:53 AM   #23
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Didn't work on my system.

Is that because I have ICQ sounds turned off or because I have Windows XP or ...?
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 09:28 AM   #24
jimmyf
OU812
 
Join Date: Feb 2001
Location: California
Posts: 12,651
I should not have any problem...as I have ICQ installed on my D: drive. but am going to check anyway.
__________________
Epic CashEpic Cash works for me
Solar Cash Paysite Plugin
Gallery of the day freesites,POTD,Gallery generator with free hosting
jimmyf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 09:36 AM   #25
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
Quote:
Originally posted by jimmyf
I should not have any problem...as I have ICQ installed on my D: drive. but am going to check anyway.
it's quite easy to run locate the file by script and pipe the result
to the next action

DynaMite
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-18-2002, 09:46 AM   #26
jimmyf
OU812
 
Join Date: Feb 2001
Location: California
Posts: 12,651
Quote:
Originally posted by DynaSpain


it's quite easy to run locate the file by script and pipe the result
to the next action

DynaMite
Like I said am going to check anyway. I did and found nothing.
__________________
Epic CashEpic Cash works for me
Solar Cash Paysite Plugin
Gallery of the day freesites,POTD,Gallery generator with free hosting
jimmyf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-21-2002, 09:04 PM   #27
easyjesus
Confirmed User
 
Join Date: Mar 2002
Location: Ft Worth TX
Posts: 291
As long as your running a firewall, and dont have the firewall set to let programs automatically do shit like that, your FINE!
__________________
Loved By Some, Hated By Most....
<a href="http://www.unclejimsporn.com">http://www.unclejimsporn.com</a>
<a href="http://www.cousindirty.com">http://www.cousindirty.com</a>
<a href="http://www.drunkspringbreakchics.com">http://www.drunkspringbreakchics.com</a>
easyjesus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-23-2002, 04:23 AM   #28
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917
I have a firewall, but it didn't block this program from being run, according to the default settings.

It didn't stop it from downloading the files since it has given ICQ the right to download sound themes (the .exe was hidden in a sound themes file). And then the html runs the hidden file (somehow - I didn't really look to see what was going on) from your own computer... I am not sure why it let this happen, but I do know that a lot of programs are run on your own computer without your permission...

Has anyone analyzed the file, yet?
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-23-2002, 05:16 AM   #29
Theo
HAL 9000
 
Industry Role:
Join Date: May 2001
Posts: 34,515
good catch!
Theo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.