Shoutbox

Dangerous quick-text exploit - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Messenger Plus! for Live Messenger (/forumdisplay.php?fid=4)
+---- Forum: WLM Plus! Bug Reports (/forumdisplay.php?fid=7)
+----- Thread: Dangerous quick-text exploit (/showthread.php?tid=34482)

Dangerous quick-text exploit by netdroid9 on 11-16-2004 at 10:07 AM

If one were to have 1000 lines of code that all executed another text, which executed a different 1000 times, that sent 4999 (this is by code I wrote, but I didn't realise it's potential untill after my msn froze from attempting to send it. one more charactor and it'ed hit 5000 (I'm using a parameter as an emoticon).)
emoticons, to a test server, it could hamper the network a small amount. do this on three to four pc's pointing at different servers, it would cause a lapse in the server it routes through. Do this with a few hundred towards different countries one at a time and it would a huge lapse in the msn network.

8-| Man I'm a nerd. Remove the ability to execute a quicktext from a quicktext to fix this.


RE: Dangerous quick-text exploit by Millenium_edition on 11-16-2004 at 04:47 PM

I think that .BAT files are dangerous and yet they still are there.

Same with this. it's a kind of "code", so of course it can crash you. It's your quicktext, not anyone elses, remember ^o) ?


RE: Dangerous quick-text exploit by Patchou on 11-16-2004 at 10:17 PM

Note that you can't ask a quick text to send 1000 lines of text, if I put limits on some thigns in Messenger Plus!, it's for that exact reason. As far as I can see, you cannotdo anythign but flood yourself and if that's the case, then it's not an exploit at all :). If found a way to flood someone to the point it completely freezes his Messenger or crashes it, using anythign in Messenger Plus!, please email me at mplus@patchou.com with the instructions to reproduce the problem. However, I feel pretty safe to say to everyone else reading this thread that the risk that this kind of thing could exist is very close to 0.


RE: Dangerous quick-text exploit by netdroid9 on 11-16-2004 at 11:39 PM

Oh... Um... I forgot about the hashs... :$
Close this thread please.