Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

[Full-disclosure] [UNTRUE] Gadu-Gadu supposedly fixed the invisible dete

Subject: [Full-disclosure] [UNTRUE] Gadu-Gadu supposedly fixed the invisible detection vulnerability?
Date: Tue, 30 Aug 2005 12:45:33 +0200
Hello,

=== Introduction ===
Today some services announced that Gadu-Gadu company fixed the
vulnerability in their servers that was used by software plugins
like "Inwigilator" from the Power Project, et. al. to detect
whether a user of the IM program is Unavailable or Invisible.

=== What is untrue ===
I am not aware what technique is used by these plugins, but
unfortunately or not, it is *still* possible to detect
whether the user is invisible using the same old technique
I discovered on 23 september 2004 (The article[1] written in Polish
is still available and the POC[2] uses libgadu[3])

=== Usage ===
Compiled POC allows you to try to detect the invisible user:

# ./gadu <your_uin> <your_password> <victim_uin>
gadu_connect: success.
Gosciu jest online!
gadu_disconnect

This shows that <victim_uin> is online. If seems unavailable
it means they are invisible.

The conditions remain constant:
- the victim must have you listed in their address book
- the victim must have image messages enabled (that is the
minimum size > 0)

The vendor was notified on in september 2004.

=== References ===
[1] http://soltysiak.com/articles/gg_ir.php
[2] http://www.soltysiak.com/gadu.c
[3] http://dev.null.pl/ekg/

--
Regards,
Maciej Soltysiak


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>
  • [Full-disclosure] [UNTRUE] Gadu-Gadu supposedly fixed the invisible detection vulnerability?, Maciej Soltysiak <=