Skip to main content

Are You Sure About Your Instant Messaging Software Safety?

Instant messaging communication is a general and simple computer process involving PC users all over the world. It exists in peer to peer, spoken, written or gesticulated form. Today I'm going to concentrate on an instant messaging type of communication due to the fact that a vulnerability was identified in Lotus Instant Messenger. I suppose most of you know what instant messaging is. In fact, the name instant messaging can speak for itself. A potential denial-of-service vulnerability can be prompted by certain malformed Secure Sockets Layer (SSL) records which make the IBM® Global Security Toolkit (GSKIT) component fail and thus provoke the application to terminate.

I suppose that most of you really know what Instant messaging is. However, in order to know more about it, let me remind you briefly what it is. Instant messaging (IM) is a form of real-time communication between two or more people based on typed text. The text is transmitted through devices connected over a network like the Internet. Next, do you know what Web conferencing is? Web conferencing is used to organize live meetings or presentations through the Internet. In a web conference, each participant sits at his or her own computer and is connected to other participants through the Internet. This can be either a downloaded application on a computer of each of the attendees, or a web-based application where the attendees go to a URL or in other words website address, to get in the conference.

So what is IBM Lotus Sametime? According to Wikipedia, IBM Lotus Sametime is a client-server application and middleware platform that offers real-time, unified communications and collaboration for enterprises. Those capabilities involve presence information, enterprise instant messaging, web conferencing, community collaboration, and telephony capabilities and integration.

Some features of Lotus Instant Messaging might be similar to other well-known instant messaging programs on the net, for example Skype or Yahoo! Messenger. One of the files related to Skype include but are not limited to the following: SkypeIEPlugin.dll. Also, some of the files related to Yahoo! Messenger might include but are not limited to the following: YAHOOM~1.EXE and ymsgr_tray.exe.

How can attackers exploit the Lotus Instant Messaging and Web Conferencing vulnerability? The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 creates error messages for a failed logon attack with different time delays which depend on whether the user account exists. This allows remote attackers to enumerate valid usernames.M3.jpg

Sametime integrates with a wide array of software, including Lotus collaboration products, Microsoft Office productivity software which incorporates Microsoft Outlook, portal and Web applications. Some of the files related to Microsoft Office might include but are not limited to the following: bcmsqlstartupsvc.exe, mofl.dll and owc11.dll. Also, some of the files related to Microsoft Outlook include but are not limited to the following: ACCWIZ.DLL, cb5.dll, DATAACC.EXE, EFD.EXE and gapi.dll. This vulnerability only affects IBM Lotus Instant Messaging and Web Conferencing (Sametime) servers that have configured SSL connections with their LDAP server. What is the solution to this security issue? In order to fix this particular problem, customers should upgrade their version of GSKit. When and how should they upgrade GSKit? What particular version of GSKit should you upgrade to? The answer is provided below:

* Sametime 2.5 and earlier versions did not contain GSKit; so no action is not needed for these customers;
* Windows servers: GSKit version 6.0.5.41 and any higher version of 6.0.5.xx does not contain the vulnerability.

Source: http://www.pc1news.com/news/0834/are-you-using-instant-messaging.html

Comments

Popular posts from this blog

Want To Get Answering Machine For Your IM?

Computer's personal often face problems when they have to take a break from their PC for some time and can’t answer to emails and instant messages. Actually, for email you can set up an autoresponder if you use Outlook software, and there’s a way out for gmail, too. But what can you do with your instant messenger? I have a lot of IM accounts for any purposes with different people in each account. So what utility can tell these people that I am out on a vacation or down with fever? Answer.im comes to the rescue by setting up an automated web based answering machine for your instant messenger. It works with MSN, ICQ, AIM, Yahoo and Google Talk as of now. How it Works Setting it up is very simple. First, hop over to http://answer.im/. Then, select your IM network (like GTalk, Yahoo, etc). Fill in your username and password and hit Login. Features Now, you can customize your automated reply and select the status you would like your account to remain at. Since the service is web based, ...

Durov: The phone of the richest man in the world was hacked through WhatsApp.

The founder of "VKontakte" and Telegram Pavel Durov said that back in November 2019 he warned about the vulnerability of the WhatsApp application, through which hackers hacked the smartphone of the richest man on the planet Jeff Bezos. Durov wrote about it in his Telegram-channel. Earlier, the company Facebook, which owns WhatsApp, noted that the businessman's mobile phone was hacked because of vulnerabilities in the operating system from Apple. At the same time, Durov is convinced that the problem is not iOS. " WhatsApp in its marketing campaign uses the words 'end-to-end encryption' as a magic spell, which itself should ensure the security of all communications. But this technology alone cannot guarantee absolute confidentiality," says the founder of Telegram. One of the drawbacks of end-to-end encryption, he says, is that backups of transmitted data are often not encrypted. In addition, says Durov, each application has "ways around...

Primus to Provide VoIP for MSN Messenger

Primus Telecommunications Group, Inc. has entered into an agreement with Microsoft Corp. to provide Voice-over-Internet Protocol (VoIP) services for MSN Messenger Service customers. Marketed as "PrimusTalk," once a user has logged into MSN Messenger Service, calls can be made by clicking on the "Make a Phone Call" link. A phone dialer will appear where a call can be made to any number -- national, international or mobile. The McLean, Va.-based Primus will provide PrimusTalk service as an Internet telephony application that can be accessed by any user accessing MSN Messenger Service. Specifically, the PC-to-phone service will be integrated with the MSN Messenger Service as an option that may be accessed by users of Microsoft client software programs. "Primus is leading the way to a carrier class era of converged communications solutions," said John Melick, co-president of Primus and one of the principal developers and implementers of the company's VoIP ...