This is a bad security problem, however it's not the worst. Most of the media articles ive read about this paint the exploit as very bad, and adds further proof that microsoft does not take security seriously.
However this is not the worst by far. Just last year there was an AIM exploit that allowed anyone to steal an aim 10 characters or less, for almost a year. The exploit was found by hypah in august 2000, it was fixed on windows platforms by january 2001, however the mac version wasn't fixed until july 2001. Around feb 2001 hypah made a prog to steal aims using the mac aol protocol on windows machines. He used it to steal 6000 aims in just a couple days, and posted them on a website. AOL knew about this and did nothing. It was another 3 months before the problem was fixed. Just a year earlier there was another aim exploit that lasted a good 6 months. You can find more info by searching google on hypah and "aim thief", or by visiting this site:
http://www.aol-files.com/breaches/index.html , the exploit im referring to is in http://www.aol-files.com/breaches/indent2k.htm
I'm not defending MS, im just saying this isnt the worst instant messenger problem ever found, and if you want to be fair about it look at the record for others such as yahoo or aim. As the authors of the msn exploit say on there site, this isn't an exploit with messenger, it's an exploit in IE that makes it possible. Once a patch comes out fixing ie, this will be a nonissue.
-gosh
|