PDA

View Full Version : Trillian flaw found



SLaY3r07
03-25-2005, 12:25 PM
"According to LogicLibrary, the vulnerability could allow malicious-code writers to do anything from shutting down individual programs on computers running Trillian to gaining complete control of a machine's operating system."

This flaw should be fixed w/ the next release of Trillian. Source (http://news.com.com/Trillian+IM+flaw+exposed/2100-7349_3-5637029.html?tag=nefd.top)

Tha Killa
03-25-2005, 12:52 PM
:eek: I'm using Trillian

matt9669
03-25-2005, 05:54 PM
Hehe, so am I . . .

Dissolved
03-25-2005, 05:55 PM
Hehe, so am I . . .


:| :(

matt9669
03-25-2005, 06:01 PM
Cerulean co-founder and CEO Scott Werndorfer said the buffer-related vulnerability is of "extremely low risk." In an e-mail sent to CNET News.com on Friday, he said that attackers would need to construct an entire fake IM software client for the sole purpose of sending a malicious request to a Trillian user. That person would then have to actually accept that message request in order for the attacker to take advantage of the flaw, he said.

Werndorfer pledged that the hole will be patched in the next release of Trillian and said that many of the buffer problems were fixed in the 3.1 version of the application. He strongly encouraged all Trillian users to "exercise extreme caution" when accepting file transfers or any other form of communication from any unknown contacts. Not real worried, paid for 3.0 Pro and I like it too much to stop using it :D

SLaY3r07
03-25-2005, 06:09 PM
Yeah I wouldn't be worried either matt, the hackers would have to go through a whole of trouble to do anything according to the article.

chilly1
03-25-2005, 06:11 PM
Maybe but now that they pointed out the how to????

matt9669
03-25-2005, 06:15 PM
Maybe but now that they pointed out the how to????LOL chilly :hehe:

Hackers trying to exploit that vulnerability would have known that information already, they wouldn't have posted it if it were considered a threat.

Disposibleteen
03-25-2005, 07:50 PM
i swtiched to gaim, trillian is a little better but i just like gaim a little more.

MaxxxRacer
03-25-2005, 08:01 PM
hope they fix it fast... i love my trillian.

SLaY3r07
03-25-2005, 08:04 PM
i swtiched to gaim, trillian is a little better but i just like gaim a little more.

I just dled gaim, I think I am gonna like it too :banana:

matt9669
03-25-2005, 08:16 PM
I just dled gaim, I think I am gonna like it too :banana:I hated it personally, especially b/c I use multiple AIM and Yahoo logins simultaneously and Trillian makes this really easy . . . but to each his own :up:

Also note a friend of mine that uses GAIM personally has noted issues with file transfers and such . . .