Login Register



[Reply]
Forum Index > AIM/ICQ Discussion
Be wary of the AIM Phoenix client AND server!
Posted on: 05-28 11:19 pm
ohhihohello57

PREFACE:

I had originally posted a thread on here regarding the potential of AIM Phoenix, both the client and server's flawed security, but unsurprisingly, iWarg decided to remove it and not address the issue AT ALL until he tried to make me out as malicious on the thread posted somewhere else. After I cleared myself out, he explained why he hadn't implemented secure authentication in the client, and all I can say that his reasoning was moot. However, he still hasn't updated us on if the issue has been addressed yet, plus I never heard word on if this issue was server-side as well.

So I'm going to take the risk of reposting the thread and hope more people can at least make it apparent to iWarg that we're not blind. If he still won't budge, then too bad for him, as at least most people will know about this SECURITY RISK, and if I'll be banned/suspended for this, then that's scummy, and I will lose all respect for iWarg because I will know by then that he just wants to save face from the issue and block it from everyone else so that no one can speak out! This is not some bug in the server, this is a security concern that affects everyone.

However, I can't post the original text here as it creates a glitched thread without the essay of a thread I typed up, so screw it, read the version I posted onto MessengerGeek (the "somewhere else") instead: https://wink.messengergeek.com/t/psa-be-wary-of-aim-phoenix/4721

Enjoy.

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
Posted on: 05-29 11:31 pm
Wildman

Beta Tester

no, you're just making assumptions about the server, and I assure you i'm not daft enough to not encrypt the password credentials in both the database and server software. which is far more than I can say for the xeon productions server software.

Hououin - your friendly neighborhood AIM server operator
Posted on: 05-30 12:25 am
ohhihohello57

That's why I label it as a POSSIBILITY. And I simply wanted your word on this to see if my claim was confirmed. I am in no way trying to outright state that you do such, but the cleartext stuff in the client does raise some red flags in terms of the server's security.

Also, I do know my DB security, thank you very much. :P

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
Posted on: 05-30 12:31 am
ohhihohello57

"I assure you i'm not daft enough to not encrypt the password credentials in both the database and server software."

Wait, ENCRYPT?!

Unless you meant hashing the passwords, then that's as bad as storing it cleartext, as you technically have access to the key to decrypt the passwords.

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
Posted on: 05-30 1:11 am
Wildman

Beta Tester

perhaps I should have said "securely store" then

Hououin - your friendly neighborhood AIM server operator
Posted on: 05-30 1:37 am
ohhihohello57

Isn't gonna help. I'd rather have specifics on what you use to store passwords than eat up vague terms that could mean anything. :/

if (Nerd->Personality == (NERD_PERSON_FRONTFACING + NERD_PERSON_SMARTALEC)) { return; }
< - 1 - >

[Reply]