What is the BigBlueNetwork?

News Categories

Post a news story

Join other instant messaging fans in our live IRC chat room. Click here to launch our java chat, or visit irc.bigblueball.com #bigblueball

Latest News

News Feeds

Add to My Yahoo!
  Help
  Help

 Got instant messaging questions? Get answers in our forums. Sign up now for free!


Front Page > Site News & Announcements > Instant Messaging News > Yahoo! Messenger News

100% Unbootability on YMSG

Posted by Ven0m Ven0m is offline on 05-02-2008, 09:50 PM  

YTK Support Forum :: View topic - How To Be Unbootable On ANY Chat Client Or ALG!

Well guys, now that a guy named LegendKiller (from Y!TunnelPro's forum) was so nice as to attempt to "Reverse Engineer" our BDP option in YTK Pro beta build 430 I'll tell you what's going on here (he looked at our external event logger and was able to figure it out).

Over the last several weeks Yahoo! has started "patching" their servers against the buffer boot exploit. Their "patch" consists of getting rid of the disconnection rule entirely when packet data is pending against you in the buffer. Nowadays if you were to be bombed with a booter you will NOT be disconnected regardless of what type the booter is (even if it's some hot new exploit it won't matter).

What does this mean?
This means that of the 61+ servers to chat on 6 of them I've found to be protected against all boots. Here is the following list of them (I tested all of them and here are my results at the time of this post):

Unbootable Servers:


- cs1.msg.dcn.yahoo.com
- cs2.msg.dcn.yahoo.com
- cs40.msg.dcn.yahoo.com
- cs50.msg.dcn.yahoo.com
- cs55.msg.dcn.yahoo.com
- cs58.msg.dcn.yahoo.com


Now that the cat's out of the bag you can use one of these servers on ANY chat program for Yahoo! Chat and be completely unbootable only as long as there's no local program flaws in your choice of chat program. Our BDP option is a TCP window scale option (at the socket level) plus a randomization of these servers (from the pool of protected servers).

Who deserves to be credited solely for this discovery? Venom, Brock and myself. Venom/Mike made me aware of the fact that certain people weren't affected by the buffer boot exploit. After looking into a couple of things I logically deduced all the complexities down to the chat servers themselves that are providing this type of protection for you.

The rest is history...
This can be done with any ALG (YTK Pro or Y!TunnelPro) or any chat clients (YahELite, Yazak, Yahaven, Y!mLite, etc.) that allows you to select which server to log in with. All you have to do is set it, and log in. :)

Last edited by detn8r : 05-04-2008 at 12:52 AM.
Reply With Quote

View Comments   Show Printable Version   Email this Page


 

Comments

Torseq Tech. says
05-03-2008, 07:09 PM
This is true folks. By using one of these servers you will be immune to server-side disconnects and boot flooding. You won't get knocked off the chat network on these servers even if you're on a dial-up connection.
Reply With Quote
Stlouisx50 says
06-27-2008, 01:23 PM
Quote:
Originally Posted by Ven0m View Post
YTK Support Forum :: View topic - How To Be Unbootable On ANY Chat Client Or ALG!

Well guys, now that a guy named LegendKiller (from Y!TunnelPro's forum) was so nice as to attempt to "Reverse Engineer" our BDP option in YTK Pro beta build 430 I'll tell you what's going on here (he looked at our external event logger and was able to figure it out).

Over the last several weeks Yahoo! has started "patching" their servers against the buffer boot exploit. Their "patch" consists of getting rid of the disconnection rule entirely when packet data is pending against you in the buffer. Nowadays if you were to be bombed with a booter you will NOT be disconnected regardless of what type the booter is (even if it's some hot new exploit it won't matter).

What does this mean?
This means that of the 61+ servers to chat on 6 of them I've found to be protected against all boots. Here is the following list of them (I tested all of them and here are my results at the time of this post):

Unbootable Servers:


- cs1.msg.dcn.yahoo.com
- cs2.msg.dcn.yahoo.com
- cs40.msg.dcn.yahoo.com
- cs50.msg.dcn.yahoo.com
- cs55.msg.dcn.yahoo.com
- cs58.msg.dcn.yahoo.com


Now that the cat's out of the bag you can use one of these servers on ANY chat program for Yahoo! Chat and be completely unbootable only as long as there's no local program flaws in your choice of chat program. Our BDP option is a TCP window scale option (at the socket level) plus a randomization of these servers (from the pool of protected servers).

Who deserves to be credited solely for this discovery? Venom, Brock and myself. Venom/Mike made me aware of the fact that certain people weren't affected by the buffer boot exploit. After looking into a couple of things I logically deduced all the complexities down to the chat servers themselves that are providing this type of protection for you.

The rest is history...
This can be done with any ALG (YTK Pro or Y!TunnelPro) or any chat clients (YahELite, Yazak, Yahaven, Y!mLite, etc.) that allows you to select which server to log in with. All you have to do is set it, and log in. :)
How can this be done with YTK PRO I see CS. Servers from 101 + but not any of the ones you mentioned above. If you can enter the servers manually I'D like to know how.
Reply With Quote
Stlouisx50 says
06-27-2008, 01:30 PM
Also I just tried those servers on Yahelite and they dont work. (non working servers)
Reply With Quote
nakedzero says
07-05-2008, 02:35 AM
These servers got patched already, dont they ?
Reply With Quote
Ven0m says
07-06-2008, 02:40 PM
All servers are patched now, and the ones listed above do not exist anymore. Yahoo changed them from the DCNs to the MUDs now. :)
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Replies Last Post
YMSG 11 protocol 0 05-23-2004 06:30 PM

 
All times are GMT -5. The time now is 08:24 PM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.