------=_NextPart_000_0016_01C5E23F.E7C54790
Content-Type: text/html;
charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
MSN =
Plus Password=20
Change Security Bypass Vulnerability
date:=20
05.11.2005
publisher: m0fo=20
(editor at sec.org.il)
<=
/SPAN>
Msn =
Plus! is=20
additional aplication for MSN Messenger. This application adding a lot =
of new=20
options into the MSN Messenger so it will be easier to use it. One of =
the=20
application's option is to set a password witch lock the application, =
lock the=20
logs, etc. its easy to set password for this, but its much easier to =
change it,=20
while someone trying to change password that already set, he doesnt =
need to=20
fill in the old password, this may cause a malicious user to take =
control over=20
the application, maybe reading your talks, locking your MSN,=20
etc.
all =
versions of that=20
MSN Plus! are vulnerable to this flow, my advice is not to use=20
it.
------=_NextPart_000_0016_01C5E23F.E7C54790--