Six holes found in AOL ICQ

Hackers can take control or shut down user PCs, warns security company

Iain Thomson

A Boston security company claims to have found six security holes in the ICQ ('I-Seek-You') instant messaging client for AOL.

The flaws include three problems with the Pop3 client, and can allow intruders to cause a variety of problems, from being able to install malware to hanging the computer by monopolising the CPU.

Advertisement

All versions of Mirabilis ICQ Pro instant messaging client, including the Mirabilis ICQ Pro 2003a release, are believed to be affected. There is no available patch for the problems.

AOL bought the ICQ system manufacturer Mirabilis in 1998.

"It doesn't need much technical ability to exploit this," said Ejovi Nuwere, senior security engineer for Core Security Technologies.

"Although there's no sign of any automated tools for script kiddies, there's little doubt that a skilled coder could build an automated exploit engine within a couple of days at most."

Before going public, Core Security Technologies said it made repeated attempts to contact AOL and developers Mirabilis with details of the problems after discovering them in March, but has received no response.

AOL in the US declined to comment beyond issuing a brief statement, which said: "We take all security related inquires seriously and are currently looking into the report."

Full details of the flaws can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes HTC's new Sense overlay for Android

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

NetGear ReadyNAS NVX

Review: NetGear ReadyNAS NVX

NetGear's four-bay compact network-attached storage gets a serious speed boost

AMD

AMD adds to six-core Opteron line up

New HE processors promise even lower power consumption

Adobe Systems

Adobe launches ColdFusion 9 and ColdFusion Builder

Firm promises enhanced developer productivity

Primary Navigation