Results 1 to 10 of 10

Thread: ** HEADS UP ** Trillian User's

  1. #1

    ** HEADS UP ** Trillian User's

    Multiple exploits discovered in Trillian (chat client).

    More at

    http://www.k-otik.com/english/advisories/2005/0221

    http://www.k-otik.com/exploits/20050302.trillian.py.php


    Some quick information :

    Remotely exploitable = YES



    Rated as : Critical

    till now no official patch is released.

  2. #2
    Senior Member
    Join Date
    Feb 2004
    Posts
    270
    /me thanks god that he got rid of trillian 3 day's ago.
    Since the beginning of time, Man has searched for the answers to the big questions: \'How did we get here?\' \'Is there life after death?\' \'Are we alone?\' But today, in this very theatre, you will be asked to answer the biggest question of them all...WHO LIVES IN A PINEAPPLE UNDER THE SEA?

  3. #3
    Hoopy Frood
    Join Date
    Jun 2004
    Posts
    662
    This is only for Trillian 3.0 and prior users. Just update your client and apparently you're protected.

    * Affected Products *
    Cerulean Studios Trillian 3.0 and prior
    - X
    "Personality is only ripe when a man has made the truth his own."

    -- Søren Kierkegaard

  4. #4
    AO Senior Cow-beller
    Moderator
    zencoder's Avatar
    Join Date
    Dec 2004
    Location
    Mountain standard tribe.
    Posts
    1,177
    Yes, trillian prompted for an upgrade recently...where did you get your "no official patch" information from?
    "Data is not necessarily information. Information does not necessarily lead to knowledge. And knowledge is not always sufficient to discover truth and breed wisdom." --Spaf
    Anyone who is capable of getting themselves made president should on no account be allowed to do the job. --Douglas Adams (1952-2001)
    "...people find it far easier to forgive others for being wrong than being right." - Albus Percival Wulfric Brian Dumbledore

  5. #5
    Greeting's

    In the advisory the "solution" part says

    "K-OTik Security is not aware of any official supplied patch for this issue."

    Anyway i did go to the official site, where on the home page it does say that trillian is upgraded to 3.1 version.

    However the download links still lead to old trillian 3.0 download file on download.com


    Link on the web-page of the publisher : http://www.trillian.cc/downloads/

    Download link leads to : http://www.download.com/Trillian/300...=dl&tag=button

    I am sorry for not doing a complete re-search before i gave the head's up.
    Parth Maniar,
    CISSP, CISM, CISA, SSCP

    *Thank you GOD*

    Greater the Difficulty, SWEETER the Victory.

    Believe in yourself.

  6. #6
    Hoopy Frood
    Join Date
    Jun 2004
    Posts
    662
    Hey, man, don't worry about it. We all screw up sometimes.

    - X
    "Personality is only ripe when a man has made the truth his own."

    -- Søren Kierkegaard

  7. #7
    Senior Member
    Join Date
    Aug 2001
    Posts
    117
    Thanks for the warning.. I was on 2.01 - getting 3.1 now. It's still the greatest chat client for Windows.
    Luck--TSM
    Atlanta, GA


  8. #8
    Hoopy Frood
    Join Date
    Jun 2004
    Posts
    662
    I upgraded from to 3.1 in December. It's still a very good chat client and some of the new features are very nice, but it still has some bugs and the new Preferences' interface is horrible compared to the old. They also took out a couple features I liked a lot.

    - Xierox
    "Personality is only ripe when a man has made the truth his own."

    -- Søren Kierkegaard

  9. #9
    Hmmm...it looks like v3.1 is vulnerable too. I just tested the exploit on v3.1 build 121 and it hung Trillian. I just checked their website and my build is the latest.

    I tested this by having my buddy create the PNG file, send it to me via IM, and then set it as my icon in Trillian. As soon as I selected it as the icon Trillian hung. Don't know if it caused a buffer overflow allowing arbitrary code to be executed because we didn't put any in the file.

    It looks like the only way you can use to attack someone is if you trick them into using the PNG file as their icon...so the risk would seem to be low....unless your too trusting. :-)

  10. #10
    Senior Member
    Join Date
    Apr 2004
    Posts
    1,024
    Trillian sucks, I'm suprised anyone still uses it. If you are looking for multi protocol IM's on Win go with miranda. Looks plain at first but look around the web and you will find TONS of pluggins and addins for it. It's only been out for around a year and there are already tons of stuff out for it.

    http://www.miranda-im.org/
    [H]ard|OCP <--Best hardware/gaming news out there--|
    pwned.nl <--Gamers will love this one --|
    Light a man a fire and you\'ll keep him warm for a day, Light a man ON fire and you\'ll keep him warm the rest of his life.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •