|
-
September 29th, 2004, 02:03 PM
#1
***HEADS UP**** AIM Users
from ISC
The handlers have received several reports that AIM messages are being used to entice users to download and view jpegs that match current signatures for the GDIplus.dll exploit.
The basic method is to attach GDI exploits to profiles on AIM. The attacker then sends messages to get the user to go look at the user profile that has a jpg with the gdiplus.dll exploit in it.
This is the message being seen "Check out my profile, click GET INFO!" But of course that would be easy to change so it is probably not worth adding to your IDS signature list.
Easy one.... Social engineering, but it can still work.
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|