What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Instant Messaging > Yahoo! Messenger Support

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 07-08-2004, 05:11 AM
Chet Chet is offline
Junior Member
 
Join Date: Jun 2004
Location: .
Posts: 8
Chet is on a distinguished road (10)
Yahoo! Messenger “Online Status” Privacy Issue

I've seen quite a few questions similar to "how does someone know I'm online even if put them on my Messenger ignore list?" being posted to several Yahoo related forums. The following privacy bulletin contains information about a flaw found in Yahoo! Messenger and the Yahoo! servers that allow this to happen if you have placed the user on your ignore list.

The information concerning the flaw has already been forwarded to Yahoo! Inc. and is expected to be fixed fairly soon.



Title: Yahoo! Messenger “Online Status” Privacy Issue
Author: Chet Simpson
Date: July 8th, 2004
Application affected: Yahoo! Messenger 5.5 (all builds)
Application affected: Yahoo! Messenger 5.6 (all builds)
Application affected: Yahoo! Messenger 6.0 (all builds)
Example included: Yes


Summary:
--------

A flaw exists in the Yahoo! Messenger client application and servers that can allow a user to add someone to their buddy list and view the targets online status if the target has ignored them.


Details:
--------

Yahoo! Messenger includes features that allow a user to ignore other people. When a user has been added to the ignore list all communications from that user are still transmitted by the Yahoo servers and are instead blocked by Messenger. Because Messenger ignores all communications from users who have been ignored anytime a blocked user attempts to add the other person as a “buddy” the operation automatically completes successfully.

Although the current architecture of the Yahoo! servers allows this operation to be completed successfully it normally does not allow the blocked user to view the online status of the person who ignored them. There are however two flaws in the Yahoo server architecture which allow a blocked user to bypass this restriction and view whether the user is online or not.

The first flaw occurs when the blocked user is removed from the ignore list. Because the original “add buddy” request was filtered by Messenger no rejection or denial operation occurred. Once the user has been removed from the ignore list the restriction prohibiting them from viewing the other persons online status is automatically removed. Although the restriction is removed the user who was added as a buddy does not receive a notification of the “add buddy” request.

The second flaw takes a little more effort but allows a blocked user to add the person who ignored them and immediately view the targets online status. This technique requires that the “attacker” create a profile ID(1) and coax their target into placing that name onto the ignore list. Once a profile ID has been added to the list of ignored users the attacker simply deletes the profile ID and the restriction to view the targets online status is automatically lifted.


Detailed Steps:
---------------

The following describes the necessary steps to add a user as a buddy and view their online status without their consent.

1. Log into http://edit.yahoo.com/config/eval_profile using an existing Yahoo ID (or create one).
2. Create a Profile ID.
3. Log into Yahoo! Messenger.
4. Contact the intended target using the profile ID and coax them into placing that name onto their list of ignored users.
5. Add the user as a buddy.
6. Delete the profile ID.
7. Log out of Yahoo! Messenger.
8. Log back into Yahoo! Messenger.

If the user is online and has not logged in using the “invisible” mode their online status will be displayed in your buddy list.


Third Party Clients:
--------------------

Third party clients that use the Ignore List feature provided through the Yahoo! Messenger protocol and/or implement their own Ignore List feature may also be at risk if they do not implement the proper handling of Add Buddy requests received from ignored users.


Work Around:
------------

The only method to avoid this flaw is to refrain from using the Ignore User list feature in Yahoo! Messenger. Until this flaw is fixed by Yahoo! Inc. users who are worried that this flaw might be used against them should change their Yahoo! Messenger Ignore List preferences to block all communications from people who are not on their buddy list. This setting allows the buddy add requests to be passed on to Yahoo! Messenger but (should) block all other communication from users who are not on your buddy list.


(1) A profile ID or alias is simply an additional username that can be used at the same time as your normal Yahoo! ID. For more information on profile ID’s see http://help.yahoo.com/help/us/pager/use/use-13.html

Reply With Quote
  #2 (permalink)  
Old 07-08-2004, 04:32 PM
tangledlisa's Avatar
tangledlisa tangledlisa is offline
Senior Member
 
Join Date: Jan 2003
Location: Columbus, Ohio, USA.
Posts: 271
tangledlisa is on a distinguished road (10)
Send a message via MSN to tangledlisa Send a message via Yahoo to tangledlisa
Thanks for the info Chet
Reply With Quote
  #3 (permalink)  
Old 07-10-2004, 06:49 AM
Wildatheart Wildatheart is offline
Banned
 
Join Date: May 2004
Location: .
Posts: 154
Wildatheart is on a distinguished road (10)
Send a message via Yahoo to Wildatheart
Well correct me if I'm wrong but isn't this where deny a buddy comes in after you place them on ignore you can then use deny a buddy to take yourself off that persons list.

And then they couldn't readd you a second time.. Or am I wrong ?
Reply With Quote
  #4 (permalink)  
Old 07-16-2004, 07:21 AM
Justified Justified is offline
Banned
 
Join Date: Feb 2004
Location: .
Posts: 134
Justified is on a distinguished road (10)
Send a message via AIM to Justified Send a message via MSN to Justified Send a message via Yahoo to Justified
There are two things you need to add to this , 1. Person A deletes their profile and Person B then decides to use deny a buddy It won't work because the PROFILE doesn't exist.

If Person A then decides to recreate the profile Person B who already has that id on ignore Can't delete themselves off of Person A's profile .

Now if you try to message the person that has you on ignore your messenger will say Session Expired please re-login and it will log you out . ( or at least MINE DOES ) if you try this and find out yours doesn't log you out could you let me know or if deny a buddy works for you on this ?
Reply With Quote
  #5 (permalink)  
Old 05-06-2005, 05:17 AM
Carriemeawayplz's Avatar
Carriemeawayplz Carriemeawayplz is offline
Member
 
Join Date: Mar 2003
Location: USA.
Posts: 69
Carriemeawayplz is an unknown quantity at this point
Send a message via MSN to Carriemeawayplz
Yahoo still hasn't fixed this security issue. It is still possible for someone to message you , you put them on ignore and then if they add you to their messenger. It accepts it without you being the wiser. They are able to see what you are doing, where you are, and your status.

Since this is the case , I am having a hard time trying to understand the whole point of ignore if it doesn't even work!
Reply With Quote
  #6 (permalink)  
Old 05-06-2005, 12:40 PM
EliteNick's Avatar
EliteNick EliteNick is offline
Senior Member
 
Join Date: Jul 2004
Posts: 343
EliteNick is on a distinguished road (10)
Send a message via AIM to EliteNick Send a message via Yahoo to EliteNick
Yahoo! needs to change it's intire approach to customer service and fixing problems. Any time you have a problem, they always just send back auto-responder e-mails. Big problems that everyone experiences, takes sometimes years for Yahoo! to become aware of and fix. That's the only thing I don't like about Yahoo!, Inc.


Art is my life
Reply With Quote
  #7 (permalink)  
Old 05-14-2005, 05:55 AM
Dobrin Dobrin is offline
Junior Member
 
Join Date: May 2005
Location: Varna , Bulgaria
Posts: 22
Dobrin is on a distinguished road (10)
Send a message via ICQ to Dobrin Send a message via MSN to Dobrin Send a message via Yahoo to Dobrin
Is this still possible to bypass the ignore ?
Reply With Quote
  #8 (permalink)  
Old 05-17-2005, 03:44 PM
Dermot's Avatar
Dermot Dermot is offline
Here to help!
 
Join Date: Dec 2004
Location: Louth, Ireland.
Posts: 1,221
Dermot is a celebrity (300)Dermot is a celebrity (300)Dermot is a celebrity (300)Dermot is a celebrity (300)
Send a message via ICQ to Dermot Send a message via AIM to Dermot Send a message via MSN to Dermot Send a message via Yahoo to Dermot
no, not in chat, its serverside and yahoo only allow 99 people on it per id.

Voice ignore is a different matter tho..

Shadow-corp.net - 1500+ Games and climbing!
Reply With Quote
  #9 (permalink)  
Old 09-18-2006, 09:26 PM
ismart ismart is offline
Junior Member
 
Join Date: Jul 2006
Posts: 10
ismart is on a distinguished road (10)
Thank you very much. it’s useful for me
Reply With Quote
  #10 (permalink)  
Old 09-19-2006, 05:28 PM
dvelez1985's Avatar
dvelez1985 dvelez1985 is offline
Senior Member
 
Join Date: Sep 2005
Location: Helotes, Texas
Posts: 231
dvelez1985 will become famous soon enough (50)
Send a message via ICQ to dvelez1985 Send a message via AIM to dvelez1985 Send a message via MSN to dvelez1985 Send a message via Yahoo to dvelez1985 Send a message via Skype™ to dvelez1985
Chet... Simpson?

Ah yes the creator of YTunnel.

Reply With Quote
Reply



Currently Active Users Viewing This Topic: 2 (0 members and 2 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
Messenger Plus! 3 BETA Review! DXtremz Windows Live Messenger Support 44 09-14-2005 01:32 PM
Yahoo Messenger 6.0 Menu ( s ) Updated vb_packets Yahoo! Messenger Support 87 09-05-2004 02:22 PM
Messenger Plus! 3 Feature List BigBlueBall News Windows Live Messenger News 0 05-21-2004 12:00 AM
Yahoo! Messenger Launches ′IMVironments′ With Next Generation of Yahoo! Messenger Service BigBlueBall News Yahoo! Messenger News 0 10-22-2001 12:00 AM

All times are GMT -5. The time now is 09:44 AM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.