It looks like another bug has been found and is located on BugTraq at http://www.securityfocus.com/archive/1/458225.
January 29, 2007
January 26, 2007
YCC Bot Maker
I am proud to announce the latest addition to the website, YCC Bot Maker. As the name implies this is a nice program to create all of those Yahoo! bots that you need. The program and source can be found under the Code section. If you do decide to try it out please stop by the forum and tell me what you think.
Spamming Wikipedia?
As a general rule I don’t like SPAM and I try not to produce SPAM myself. I have run across one exception to my rule. I don’t know if this would even be considered SPAM but I think will be a valuable addition to advertising this site.
A ran across an article in Wikipedia about the Yahoo! Messenger protocol located at http://en.wikipedia.org/wiki/Yahoo%21_Messenger_Protocol and a related article at http://en.wikipedia.org/wiki/YMSG. They are both good and provide a basic understanding of the protocol. I feel that I may have something to add to the topic so I added a link to ycoderscookbook.com to the bottom. I’m not sure if it is in the true spirit of Wikipedia to add your own links but I figure if it’s not someone will edit it.
As noted in the article, this is almost an exact copy from a document in libyahoo2 (http://libyahoo2.sourceforge.net/). I don’t want to take from the original but I think some of my diagrams located in the tutorials section may be a better illustration than the current ASCII drawings. If I get a chance I may do some Wiki editing to improve the overall experience.
P.S. Since adding the link, Wikipedia has become the number one referral.
January 9, 2007
More Detail
Here is a slightly more detail description of the Messenger YMailAttach vulnerability. http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=456
January 5, 2007
Dropping Like Flies
I was reviewing my logs today and all I can say is wow. There are all kinds of accesses to my blog and forums and I wondered what was going on. I soon realized that it was the automated bot army knocking at my door again. The only difference this time was when they knocked, the bug zapper got them and they dropped like flies. Truth be told I had no idea what was up until I review the logs.



