Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] [UNTRUE] Gadu-Gadu supposedly fixed the invisible detection vulnerability? |
|---|---|
| Date: | Tue, 30 Aug 2005 12:45:33 +0200 |
Hello, === Introduction === Today some services announced that Gadu-Gadu company fixed the vulnerability in their servers that was used by software plugins like "Inwigilator" from the Power Project, et. al. to detect whether a user of the IM program is Unavailable or Invisible. === What is untrue === I am not aware what technique is used by these plugins, but unfortunately or not, it is *still* possible to detect whether the user is invisible using the same old technique I discovered on 23 september 2004 (The article[1] written in Polish is still available and the POC[2] uses libgadu[3]) === Usage === Compiled POC allows you to try to detect the invisible user: # ./gadu <your_uin> <your_password> <victim_uin> gadu_connect: success. Gosciu jest online! gadu_disconnect This shows that <victim_uin> is online. If seems unavailable it means they are invisible. The conditions remain constant: - the victim must have you listed in their address book - the victim must have image messages enabled (that is the minimum size > 0) The vendor was notified on in september 2004. === References === [1] http://soltysiak.com/articles/gg_ir.php [2] http://www.soltysiak.com/gadu.c [3] http://dev.null.pl/ekg/ -- Regards, Maciej Soltysiak _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] Out of Office Reply - Julie Terranson, winsoc |
|---|---|
| Next by Date: | Re: [Full-disclosure] Out of Office Reply - Julie Terranson, John Smith |
| Previous by Thread: | Re: Out of Office AutoReply: [Full-disclosure] Julie Terranson, poo |
| Next by Thread: | Re: [Full-disclosure] Out of Office Reply - Julie Terranson, John Smith |
| Indexes: | [Date] [Thread] [Top] [All Lists] |