AOL fixes major security hole

By D. Ian Hopper

Associated Press

WASHINGTON – As AOL Time Warner engineers opened their presents and spent time with their families, a team of young hackers planned a holiday surprise: a major security hole in one of the company’s flagship programs.

The international group released a program that turns AOL’s Instant Messenger into a key that could unlock many home computers. Now the hackers are being criticized by security experts for not giving AOL sufficient time to react.

The group, founded by a 19-year-old Utah college student, discovered a security hole in AOL’s Instant Messenger program that could have let a hacker take control of a computer. AOL fixed the problem at its central networks today.

“The issue was resolved early this morning and was handled on the server side, so users do not have to download anything or take any other action,” AOL spokesman Andrew Weinstein said. “To our knowledge, no users were affected by this issue prior to its resolution.”

The problem affected the newest as well as many earlier versions of AOL’s Instant Messenger program, which boasts more than 100 million users.

“You could do just about anything: Delete files on the computer or take over the machine,” said Matt Conover, founder of the hackers’ group, “w00w00.”

Conover said w00w00 has more than 30 active members from 14 states and nine foreign countries.

Conover, who attends Utah State University, said the group found the problem several weeks ago but didn’t contact AOL until after Christmas. The group got no response from AOL to an e-mail sent during the holiday week, he said, so w00w00 released details – and a program that takes advantage of it – to public security mailing lists less than a week later.

The program released by w00w00 remotely shut down a user’s Instant Messenger program but could have been modified to do more sinister things.

That practice is under scrutiny by security professionals. While some independent researchers argue for a “full disclosure” policy and say software vendors are trying to hide their mistakes, many companies say users are better protected if companies have time to react.

“I think that’s pretty dangerous,” said Chris Wysopal of the security company AtStake, “especially since they pretty much acknowledged that they hadn’t gotten a response back from AOL yet.”

Russ Cooper, who moderates a popular security mailing list and works for the security firm TruSecure, said Conover’s action was irresponsible because it helped hackers.

“I think it’s better to provide details of the exploit and then let other people write the actual code,” Cooper said. “It lets the technical community have the information they need without letting idiots have the information they want.”

Conover said w00w00 set a New Year’s deadline for sentimental reasons, because it was the anniversary of the group’s last major security release. He defended the disclosure of the attack program because “it means providing all the information we have available to the security community.”

AOL’s Weinstein said the company would have appreciated more warning.

“We’d encourage any software programmer that discovers a vulnerability to bring it to our attention prior to releasing it,” Weinstein said.

Copyright ©2002 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Logo for news use featuring Snohomish County, Washington. 220118
Health officials: Three confirmed measles cases in SnoCo over holidays

The visitors, all in the same family from South Carolina, went to multiple locations in Everett, Marysville and Mukilteo from Dec. 27-30.

Dog abandoned in Everett dumpster has new home and new name

Binny, now named Maisey, has a social media account where people can follow along with her adventures.

People try to navigate their cars along a flooded road near US 2 on Wednesday, Dec. 10, 2025, in Sultan, Washington. (Olivia Vanni / The Herald)
Temporary flood assistance center to open in Sultan

Residents affected by December’s historic flooding can access multiple agencies and resources.

Logo for news use featuring the Tulalip Indian Reservation in Snohomish County, Washington. 220118
Teens accused of brutal attack on Tulalip man Monday

The man’s family says they are in disbelief after two teenagers allegedly assaulted the 63-year-old while he was starting work.

A sign notifying people of the new buffer zone around 41st Street in Everett on Wednesday, Jan. 7. (Will Geschke / The Herald)
Everett adds fifth ‘no sit, no lie’ buffer zone at 41st Street

The city implemented the zone in mid-December, soon after the city council extended a law allowing it to create the zones.

A view of the Eastview development looking south along 79th Avenue where mud and water runoff flowed due to rain on Oct. 16, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
Eastview Village critics seek appeal to overturn county’s decision

Petitioners, including two former county employees, are concerned the 144-acre project will cause unexamined consequences for unincorporated Snohomish County.

Snohomish County commuters: Get ready for more I-5 construction

Lanes will be reduced along northbound I-5 in Seattle throughout most of 2026 as WSDOT continues work on needed repairs to an aging bridge.

Logo for news use featuring the municipality of Snohomish in Snohomish County, Washington. 220118
Snohomish man held on bail for email threat against Gov. Ferguson, AG Brown

A district court pro tem judge, Kim McClay, set bail at $200,000 Monday after finding “substantial danger” that the suspect would act violently if released.

Kathy Johnson walks through vegetation growing along a CERCLA road in the Mt. Baker-Snoqualmie National Forest on Thursday, July 10, 2025 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Activism groups to host forest defense meeting in Bothell

The League of Women Voters of Snohomish County and the Pacific Northwest Forest Climate Alliance will discuss efforts to protect public lands in Washington.

Debris shows the highest level the Snohomish River has reached on a flood level marker located along the base of the Todo Mexico building on First Street on Friday, Dec. 12, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
SnoCo offers programs to assist in flood mitigation and recovery

Property owners in Snohomish County living in places affected by… Continue reading

Logo for news use featuring Snohomish County, Washington. 220118
Snohomish County declares measles outbreak, confirms 3 new cases

Three local children were at two Mukilteo School District schools while contagious. They were exposed to a contagious family visiting from South Carolina.

Logo for news use featuring Snohomish County, Washington. 220118
Another Snohomish County family sues Roblox over alleged child safety issues

Over two months after Dolman Law Group filed a complaint alleging the platform instills a false sense of child safety, another family alleges the same.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.