AIM security tool opens back doors

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
A tool recommended by a security group to squash the bugs in America Online's Instant Messenger application actually had secret back-door code that allowed the author to, among other things, redirect browsers to porn sites. The security group w00w00, which discovered last week's serious flaw in AOL's instant messenger software, said on Tuesday that a program that could act as a temporary Band-Aid for the AIM problem had in reality been misrepresented by the person who posted it to the Bugtraq mailing list late last month. "Any software that is released to the public, or even privately, should do what it's advertised to do and nothing else," Tim Yardley, a software engineer and w00w00 member, said in an email. On the good side, the program, AIMFilter, intercepted data sent to and from AOL's instant messaging servers and threw away potentially harmful code used by hackers. Yet, the application also sent the IM user's Internet address to its author, connected to two different pay-for-click sites to generate income for the author and gave potential intruders the ability to redirect the AIM user to a small number of different porn sites. Yardley and other w00w00 members were particularly put out by their discovery, as the group had said the tool provided a solution to the hole they had found in AOL's AIM software last week. That flaw could have given potential intruders full control over an AIM user's computer. "People should not be coding in back doors, money-generating schemes, or other covert options into applications," Yardley said. Still, a host of potential security risks remain in AIM, and a tool like AIMFilter could actually make a computer more secure, so Yardley cleaned up the code and posted a modified version of it to the Bugtraq list. For his part, AIMFilter's author, 16-year-old high-school student Robbie Saunders, said he had no malicious intent. "It started out as a little thing to crash my friends," he said in an email to CNET News.com. "My intentions were to get AIM to fix the exploits and for people to enjoy my software." Saunders posted the original message, which had a link to his site and the code, on 30 December. In that message, he described several bugs in AOL's Instant Messenger application that could have potential security implications. He claimed that his tool would block any attempts by online vandals to exploit the bugs. Yet Saunders admits the tool does a lot more. "All my software really did was contain admin commands, letting my (AOL) screen name get an (annoying) user's IP address to report them to an ISP and to kick a user off of the filter," he wrote in the email. In addition, he said that w00w00's claim that the program sent data equivalent to a mouse-click to two click-for-profit sites on his behalf was also true. "The cash-paid click-throughs are because I need money," he said in a statement on his Web site. They only go in once (when you open the filter) and not on time intervals like w00w00 claims." In various postings, members of w00w00 said they believed the program would attempt to connect to the sites every so often. As for the porn, Saunders said on his site that the ability to remotely cause the software to redirect browsers to the porn pages was intended to punish anyone who "mess(ed) with my friends." Despite the admissions, though, Saunders seemed unrepentant. "I didn't expect people to care," he said in his email. "Only I could use (the backdoor functions), and no damage or lost information could come to (people's) computers through using the filter." Yet, w00w00 members were not appeased. "Being poor is certainly no excuse for building in and not disclosing the existence of personal profit-generating code," said Jordan Ritter, a consultant and member of w00w00, pointing out that companies get routinely lambasted for putting such surreptitious functions into their programs. Part of the group's ire, however, springs from its faux pas in recommending a piece of software that they had not thoroughly checked out. "We apologise to the security community at large for this mistake," Ritter wrote in an email to the Bugtraq list. "We think this is a very apt example of why closed-source programs can be deadly." Originally, Saunders only released the actual AIMFilter program, not the code. Open-source advocates view such "closed" programs as more difficult to inspect, making their security harder to verify. It was only after Saunders released his code that the w00w00 programmers were able to audit it and find the problems. The lesson for the average user, as always on the Internet, is a caveat emptor: Let the buyer beware, said Elias Levy, chief technology officer for SecurityFocus, the company that runs the BugTraq list. "If you are going to be recommending a certain tool to plug security holes, you have to be sure that it's not going to be introducing new vulnerabilities," he said. For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 hour ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

7 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

9 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

9 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

11 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

11 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

12 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

13 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

13 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

14 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

14 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

14 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

14 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

17 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

18 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

19 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

20 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

21 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

22 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule