ICQ can be fed crafted updates


Recommended Posts

ICQ can be fed crafted updates

Because the Instant Messaging client ICQ fails to verify the authenticity of updates downloaded from the web, it is possible to substitute trojans for genuine updates. An attacker would, however, need to be able to reroute the resolution of the IP address for update.icq.com to his own server by, for example, interfering with the router or cache poisoning the DNS server.

Shortly after installation, ICQ searches for and downloads updates. Because updates are not carried out via a secure SSL connection with certificate verification and are not signed, it is possible to insert third party files. Daniel Seither, who discovered the problem, has written two Python tools to illustrate the problem.

http://www.h-online.com/security/news/item/ICQ-can-be-fed-crafted-updates-1170607.html

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...