Trillian Vulnerability - Security Flaw Found in Trillian IM Client   3/25/2005 - 1,326 views, 4 Comments

Summary: CNet news is reporting today that a potentially serious security flaw has been found in the Trillian instant messaging client. Trillian is an instant messaging (IM) software which allows users to interact with people using many different IM services, such as ...

Previous Article « Reader Has Novel Idea - Poll: Could it Work?
Read Next Article » Yahoo Messenger Target of Effective Phishing Scam

CNet news is reporting today that a potentially serious security flaw has been found in the Trillian instant messaging client. Trillian is an instant messaging (IM) software which allows users to interact with people using many different IM services, such as AOL Instant Messenger and MSN Messenger, using just one instant messaging client (Trillian) instead of having to run each instant messenger software for each service separately.

A large number of people use Trillian, and not surprisingly, as it has been estimated that at least 25% of home users instant message with people on at least two different IM networks at the same time.

The security hole discovered in Trillian will allow a malicious hacker to shut down programs running on the target machine, and even to take control of the entire computer.

Trillian’s CEO, Scott Werndorfer, played the flaw down as being “extremely low risk”, stating that the hacker would need to create a fake instant messaging software, then send a message to the Trillian user, and then have the user accept the message. Aunty’s not so sure that would be so difficult for even the average script kiddie, let alone today’s sophisticated hacker.
Werndorfer also promised that the hole would be fixed in the next release of Trillian, and cautioned users in the meantime to be very careful when accepting file transfers and other communications from people who are not known to them.

This seems to be the month for instant messenger attacks, with worms targetting MSN Messenger and phishers attacking Yahoo Messenger.

Previous Article « Reader Has Novel Idea - Poll: Could it Work?
Read Next Article » Yahoo Messenger Target of Effective Phishing Scam

Get a FREE summary of the week's articles every Friday!
(You can stop it any time!)
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Be sure to watch for the confirmation email!

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Yahoo Messenger Target of Effective Phishing Scam

»  Two Internet Worms Target MSN Instant Messenger Users

»  Windows Help Vulnerability Target of Newly Released Trojan

»  Microsoft Announces Patch for “Help Flaw” Security Hole

For additional similar stories check out our archives on Security

 

4 Comments »

  1. Darn! But I can’t give up Trillian for AIM.

    Comment by The Mu — 3/25/2005 @ 11:57 am

  2. It only affects the Yahoo Messenger component, and you have to accept a file transfer request.

    Comment by The Wizard — 3/27/2005 @ 7:35 am

  3. I switched to Jabber protocol and I’m currently using Psi as my instant messaging client. Much happier ever since.

    Comment by Sentinel — 3/27/2005 @ 8:25 am

  4. I’ve switched to Jabber protocol and I am using Psi as my main instant messaging client now. Much happier ever since. I’ve been using MSN before but it is too childish and too many viruses and worms come to your computer thru it.

    Comment by Sentinel — 3/27/2005 @ 8:27 am

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
The Internet Patrol
Patrolling the Internet for You!