Peaches Posted January 18, 2011 Report Share Posted January 18, 2011 ICQ can be fed crafted updates Because the Instant Messaging client ICQ fails to verify the authenticity of updates downloaded from the web, it is possible to substitute trojans for genuine updates. An attacker would, however, need to be able to reroute the resolution of the IP address for update.icq.com to his own server by, for example, interfering with the router or cache poisoning the DNS server. Shortly after installation, ICQ searches for and downloads updates. Because updates are not carried out via a secure SSL connection with certificate verification and are not signed, it is possible to insert third party files. Daniel Seither, who discovered the problem, has written two Python tools to illustrate the problem. http://www.h-online.com/security/news/item/ICQ-can-be-fed-crafted-updates-1170607.html Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.