Instant messaging falls prey to hackers

They're out of the chat rooms and after your 'buddies'

Dinah Greek

Hackers are exploiting browser security flaws to hijack instant messaging (IM) accounts, security experts have warned.

When Microsoft decided to shut down its chat rooms for security reasons, it suggested IM as an alternative.

Advertisement

But although the company claims this method of chat is safer, hackers hav already exploited security holes in the Internet Explorer browser to hijack IM accounts, according to Drew Copley, a research engineer at eEye Digital Security, who discovered the original security vulnerability.

This could open a back door to unknown chatters as well as expose children to pornography from spammers.

Internet security firm Symantec said vulnerabilites have meant that attacks on IM and peer-to-peer sites have risen 400 per cent since 2002.

Using what are known as application programming interfaces (a set of routines, protocols, and tools for building software applications), hackers have developed worms or Trojans that can capture a remote user's list of IM correspondents, or 'buddies'.

By grabbing a user's buddy list rather than scanning for vulnerable IP addresses, these worms have the potential to be more virulent than predecessors like Code Red, Slammer or Blaster, which spread over the internet rather than over IM networks, warned Neal Hindocha of Symantec Security Response.

Usually the victim is led to a website, either by a distributing link through IM or via an email with a link to the webpage, which then automatically downloads a worm or trojan.

One program, according to security bulletin BugTraq, hijacks an already running AOL IM (AIM) account, changes the password and sends a message to the buddies list with a link to a malicious web page.

Another attack on users of AIM is being accomplished by sending them to a website where a trojan downloads an automated dialler. Users accessing the internet via dial-up accounts are then switched to premium rate porn numbers.

A similar worm that spreads through the Microsoft MSN Messenger system, according to South Korean antivirus company, Global Hauri. This attempts to connect to a porn website and also sends itself to names in the victim's contact list.

At the time of going to press neither AOL nor Microsoft had returned calls for comment.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

AOL offers workaround for Messenger flaw

Vulnerability affects all Windows versions of AIM software

Bugwatch: How to stop a bullet

Some promising alternatives to signature-based antivirus software

IM firm pushes into Europe

FaceTime Communications to combine instant messaging and P2P technology

Ex-hackers 'rubbish at security'

Don't employ former hackers to safeguard systems, warn experts

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation