Jun 2008
YTK Pro v 1.5 Beta Build 474 released!
24/06/08 09:52 PM Filed in: Program News
Release Notes:
- Fixed a potential boot issue with forged Yahoo! Mobile Add Buddy Rejections. These rejection packets are now blocked inside YTK Pro.
A Denial of Service Exploit is going around
22/06/08 04:26 PM Filed in: Security
Developers at Torseq Technologies have discovered 2 vulnerabilities in Yahoo Messenger Protocol in the form of a malformed “Add Buddy” packet. As it stands, the vulnerabilies require a patch from Yahoo! in order to block the attacks.
Symptoms include the inability to complete the login process ie. looping disconnect - which eventually leads to the victims account being locked.
Support Staff have published 2 workarounds to end the loop using a series of easy to perform steps. One without YTK Pro, the other using YTK Pro’s Protocol reversion.
Without YTK Pro
With YTK Pro (works with Yahoo Messenger Builds 7.0.0.242 - 8.1.0.421)
Symptoms include the inability to complete the login process ie. looping disconnect - which eventually leads to the victims account being locked.
Support Staff have published 2 workarounds to end the loop using a series of easy to perform steps. One without YTK Pro, the other using YTK Pro’s Protocol reversion.
Without YTK Pro
- Log the affected ID into http://mm.yahoo.com
- Log into the WAP Messenger
- Click on the green link consisting of notifications.
- Deny the add buddy request. (If there's more than one exploit buddy request, click on Home and then click on any new notifications and deny any other buddy requests).
- Sign back into Messenger.
With YTK Pro (works with Yahoo Messenger Builds 7.0.0.242 - 8.1.0.421)
- Open YTK Pro + Yahoo! Messenger
- Sign in on the affected ID
- Hit Cancel before the Sign In occurs or simply Sign Out but do not close Yahoo! Messenger
- Open the "YTK Control Panel"
- Under Anti-Boot put a check mark in "Enable YMSG Protocol Reversion Messenger” and select YMSG version "12"
- Under Advanced Options make sure the "YMSG Server Selector" is set to "Let Messenger Choose"
- After Sign In is successful without a disconnection - Sign out of Yahoo! Messenger go to the YTK Control Panel, Anti-Boot and uncheck "Enable YMSG Protocol Reversion Messenger should connect and use YMSG version".
--
We had already reported the vulnerabilities to Yahoo but after numerous failed attempts to contact then we have decided to go public with this. Finally, we’ve taken other steps to get a vendor patch as soon as possible such as reported the vulnerabilities to security websites such as BugTraq.
Full write up here.
We will attempt to keep you as up to date as possible in our support forum.
YTK Pro v 1.5 Beta Build 470 released!
17/06/08 09:51 PM Filed in: Program News
Release Notes:
- Webcam Presence Verification bug fixes
- New Icons
YTK Pro v 1.5 Beta Build 460 released!
12/06/08 10:23 AM Filed in: Program News
Release Notes:
- Added a brand new (and quite remarkable as it's the first to ever be done) feature called Webcam Presence Verification Scanning. This feature in itself will eliminate most of the "porn bots" in Yahoo! Chat rooms and requires very little bandwidth. This feature can be found in YTK Pro's control panel under User Scanning.
- Added support for the newest build of Messenger's permanent ignore feature. You can now "Ignore" users from the Blocked Message Archive (YTK Pro's Blocked but Saved Messages) and it'll add users to the Global Ignore Bin correctly.
YTK Pro v 1.5 Beta Build 454 released!
06/06/08 07:49 PM Filed in: Program News
Release notes:
- Compatibility added for chat server changes. Full notes available in the Support Forum Announcements.
YTK Pro v 1.5 Beta Build 452 released!
02/06/08 11:14 PM Filed in: Program News
Release Notes:
- YTK Pro build 1.5.452 adds full compatibility with Yahoo! Messenger v9.0 beta build 1389
