Home » Tech and Culture

Yahoo! Messenger reveals your IP address

28 August 2005 76 views 2 Comments

I just realized that the latest version of Yahoo! Messenger suffers from a vulnerability that allows a hacker to get your IP address.

Basically, if both the clients use the latest version of messenger and the victim responds to an IM from the attacker, the former’s IP address is shown in the netstat output of the latter. This is a very old vulnerability that was supposedly patched a long time ago, but has resurfaced in the latest version of the messenger software.

It appears that both the clients initiate a direct end-to-end connection whenever a conversation is begun. I have noticed this behavior when I communicate with some of my friends on messenger. I can see their IP address.

This is a serious issue, and I hope Yahoo! addresses it pretty soon.

2 Comments »

  • semko said:

    hacks

  • semko said:

    ########### eroigf0e_hacks

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.