Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Private IP address with yahoo messenger

Subject: Re: Private IP address with yahoo messenger
Date: Thu, 24 May 2007 16:10:46 +0530
Hi Vivek,
Thanks for your attention.
Sorry, but I think it's not something I was expecting for.

In my question, by saying "chat session" - I mean just a "chat session". No file transfer/ video/ voice chat. Simply typing the text in chat window.

[I]a <-------->Yahoo server(s) <-------> b[target]

A thing that comes in my mind is something that may allow me to do thorough forensic analysis of the packets coming from target. But I'm not very sure on what tool/s to be used and about the technique.

Hope I've made my question clear.
Warm regards.

Vivek P wrote:
Hi

I had been testing on this for quiet some time now. In versions of
yahoo messenger before 6, when i transfer a file >2 mb and try netstat
-a -n from CMD on windows machine, i was able to get the IP address
(internal) of the person at the other end !!

Yahoo did some patches in the latest editions but, i have been
informed by my testing team that burp proxy can get the target IP
(internal) if you have it installed, when using latest edition to do
file transfer,

Also when you do calls using messenger point to point connection is made.

it is like

normal chat
a <-------->Yahoo server(s) <-------> b

Lengthy processes (filetransfer) (calls) etc.
a<------->Yahoo authenticates at interval<----->b
a<------->b //Direct connection.


I think it would help, please revert so that i can get you some video demonstations to prove my experiment.


Thanx

<Prev in Thread] Current Thread [Next in Thread>