Tuesday, July 10, 2007

MSN Messenger 0day

MSN Messenger 8.x has a rather scary bug that is being exploited by people online.  When any of the strings given below are pasted into the private message box on your MSN Messenger, your Messenger will immediately disconnect.  It happens so quickly that you will think that it has not connected in the first place.

If any of your friends asks you to paste the following in your personal message, do not do this, and if for any reason you have done this then have a look at the temporary workaround mentioned below. Temporary because Microsoft have not yet given a patch for this.

Exploit:

n—a_Á—ay±m—aÁÇáç±Çáß±Çá§ÁaÇáDZOÇá—±Ç᧱Çár×ÁÇ á+NÇ áLáÇá

OR

(Error) 'A


Workaround:


There are a couple of workarounds for this bug in case you have been a victim.
First is to delete the following folders from your computer and then sign in

C:\Documents and Settings\Username\Application Data\Microsoft\MSN Messenger
C:\Documents and Settings\Username\Local Settings\Application Data\Microsoft\MSN Messenger
C:\Documents and Settings\Username\Local Settings\Application Data\Microsoft\Windows Live Contacts
C:\Documents and Settings\Username\Contacts\

Second is to login using any web messenger and remove the message in the private message area.

This bug exists only in Windows Live Messenger 8.x so using previous versions will also solve the problem.

No comments: