What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Instant Messaging > AIM Support

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #11 (permalink)  
Old 04-02-2004, 06:33 AM
sylikc sylikc is offline
Junior Member
 
Join Date: Apr 2004
Location: .
Posts: 3
sylikc is on a distinguished road (10)
WhiteMateria

that is an insanely long post, and it covers all the ins and outs of security.

In item #6, you mentioned AIM Encrypt, which is inherently insecure because everyone uses the same certificate. AIMEncrypt.com's certificate or any other that anyone can download is a very insecure way to do encryption in AIM. Knowing the internals of public-key cryptography, everyone with the same key really isn't secure. You can do encryption with OpenSSL securely instead.

Creating certificates with OpenSSL on Linux/Unix platforms are quite easy. But if you're using Windows, not all hope is lost. I've looked everywhere for instructions to create your own self-signed certificate, and since there isn't really a page out there that did it, I wrote my own.

Here are some instructions to create your own self-signed certificate for AIM. You don't need anything special, I put up the binary that allows you to do it with OpenSSL. You can use any OpenSSL binary, I provide instructions on how to use your own binary as well. If the instructions scare you, there is a program (SSCC) provided that can do it all for you. It asks you for some info you want in your certificate, and with a few clicks, you'll be on your way.


Then, after you create the .p12 package that AIM accepts, just import it and tell me what you think


URL is at:

http://secure.sylikc.net:8080/self_signed/
or just http://sylikc.net/?secure, and find the HOWTO on the bottom.

Now then you won't have to use a freely downloadable (insecure) certificate, just DIY.


However, beyond that, all that stuff is extremely useful advice. Really neat post. Especially the part about explaining social engineering to get passwords and information
Reply With Quote
  #12 (permalink)  
Old 10-04-2004, 11:47 PM
shkbobo shkbobo is offline
Junior Member
 
Join Date: Oct 2004
Location: .
Posts: 4
shkbobo is on a distinguished road (10)
Nice post but damn your screenname has to be like the same calibre of significance as say - the pin number of your main credit card for that kind of security lol. Nice way to put it all together though, most of the knowledge I have about AIM securities are there and if I know anything besides that its just details that addon to that. Good job, btw I recommend Steganos Security Suite (newest generation 7?). It has a password generator where you can select the exact specs of your password [use lowercase, use uppercase, use numbers, use special characters (alt codes, ASCII, unicode?), and select the number of characters (up to 100). When full options are selected I believe a 21 character password (132 bits) would be unbreakable even by, as they say "secret services (MAXIMUM security)." Now you can IM your local FBI agent and tell him you talk to osama bin laden daily - although he will probably have a wiretap in before you wake up the next morning, what a shame. Also, steganos comes with superb security features along with a password manager to safely store those nice 16 random character passwords...but yes I know...most of you can easily remember those. xD
Reply With Quote
  #13 (permalink)  
Old 07-30-2005, 07:11 PM
not2bright not2bright is offline
Junior Member
 
Join Date: Jul 2005
Posts: 1
not2bright is on a distinguished road (10)
Quote:

9. Two names at once
While it may seem like a good thing it can also be an invasion of privacy. Unofficial AIM clients will NOT alert you of 2 or more people signed on your name. In fact AIM may not alert of you of this ethier. If another person is logged on as you they can see to EVERYTHING another person types to you. However they cannot hear what you type back to that person. Think in terms of a Y connection and you will see what I'm talking about.




How would I know if someone signs in using my screen name? I guess what I am asking is which AIM clients do not alert?

thank you
Reply With Quote
  #14 (permalink)  
Old 07-31-2005, 05:17 PM
user91c
 
Posts: n/a
Quote:
Originally Posted by not2bright
How would I know if someone signs in using my screen name?
now a days AOLSystemMsg (the screenname) should IM you if you are logged on in two places (which would also allow unofficial clients that support IM to send you a warning). if you are really paranoid you can send a "1" to AOLSystemMsg every time you login (manually). this will cause all other logons of your screenname to be signed off.
Reply With Quote
  #15 (permalink)  
Old 08-02-2008, 06:05 PM
Jason Doc Jason Doc is offline
Junior Member
 
Join Date: Aug 2008
Posts: 7
Jason Doc is on a distinguished road (10)
Hey there WhiteMateria

Can you PM me your AIM so I can tell you somthing?

If not I can post it here :P
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
Latest & most useful AIM programs Someguy03 AIM Support 15 10-05-2008 03:15 PM
Cyber Stalking - How to put the lockdown on it! WhiteMateria Online Privacy, Safety & Security 16 03-05-2006 09:22 PM
Plenty of IM Security Holes Left to Plug BigBlueBall News General / Other IM News 0 10-31-2003 01:00 AM
IMSecure Pro by ZoneLabs BLACK HAT Online Privacy, Safety & Security 2 08-13-2003 10:13 AM
AOL IM Security Hole: Sign of Things To Come? BigBlueBall News AIM News 0 10-05-2001 01:00 AM

All times are GMT -5. The time now is 03:33 AM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.