AOL fixes major security hole

By D. Ian Hopper

Associated Press

WASHINGTON – As AOL Time Warner engineers opened their presents and spent time with their families, a team of young hackers planned a holiday surprise: a major security hole in one of the company’s flagship programs.

The international group released a program that turns AOL’s Instant Messenger into a key that could unlock many home computers. Now the hackers are being criticized by security experts for not giving AOL sufficient time to react.

The group, founded by a 19-year-old Utah college student, discovered a security hole in AOL’s Instant Messenger program that could have let a hacker take control of a computer. AOL fixed the problem at its central networks today.

“The issue was resolved early this morning and was handled on the server side, so users do not have to download anything or take any other action,” AOL spokesman Andrew Weinstein said. “To our knowledge, no users were affected by this issue prior to its resolution.”

The problem affected the newest as well as many earlier versions of AOL’s Instant Messenger program, which boasts more than 100 million users.

“You could do just about anything: Delete files on the computer or take over the machine,” said Matt Conover, founder of the hackers’ group, “w00w00.”

Conover said w00w00 has more than 30 active members from 14 states and nine foreign countries.

Conover, who attends Utah State University, said the group found the problem several weeks ago but didn’t contact AOL until after Christmas. The group got no response from AOL to an e-mail sent during the holiday week, he said, so w00w00 released details – and a program that takes advantage of it – to public security mailing lists less than a week later.

The program released by w00w00 remotely shut down a user’s Instant Messenger program but could have been modified to do more sinister things.

That practice is under scrutiny by security professionals. While some independent researchers argue for a “full disclosure” policy and say software vendors are trying to hide their mistakes, many companies say users are better protected if companies have time to react.

“I think that’s pretty dangerous,” said Chris Wysopal of the security company AtStake, “especially since they pretty much acknowledged that they hadn’t gotten a response back from AOL yet.”

Russ Cooper, who moderates a popular security mailing list and works for the security firm TruSecure, said Conover’s action was irresponsible because it helped hackers.

“I think it’s better to provide details of the exploit and then let other people write the actual code,” Cooper said. “It lets the technical community have the information they need without letting idiots have the information they want.”

Conover said w00w00 set a New Year’s deadline for sentimental reasons, because it was the anniversary of the group’s last major security release. He defended the disclosure of the attack program because “it means providing all the information we have available to the security community.”

AOL’s Weinstein said the company would have appreciated more warning.

“We’d encourage any software programmer that discovers a vulnerability to bring it to our attention prior to releasing it,” Weinstein said.

Copyright ©2002 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

The Sana Biotechnology building on Tuesday, Aug. 19, 2025 in Bothell, Washington. (Olivia Vanni / The Herald)
Bothell loses planned biotechnology manufacturing plant

New biotechnology manufacturing jobs in Bothell are on indefinite hold.

Two troopers place a photo of slain Washington State Patrol trooper Chris Gadd outside district headquarters about 12 hours after Gadd was struck and killed in a crash on southbound I-5 on March 2 in Marysville. (Ryan Berry / The Herald)
One More Stop targets drunk driving this weekend in honor of fallen trooper

Troopers across multiple states will be patrolling from 4 p.m. Friday to 5 a.m. Monday.

Students walk outside of Everett High School on Wednesday, Sept. 17, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
SnoCo students perform well on metrics, state data shows

At many school districts across the county, more students are meeting or exceeding grade-level standards compared to the state average.

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Everett council rebukes Kroger for plans to close Fred Meyer store

In the resolution approved by 6-1 vote, the Everett City Council referred to store closure as “corporate neglect.”

Logo for news use featuring the municipality of Arlington in Snohomish County, Washington. 220118
A divided Arlington City Council votes to reduce SkyFest grant by half

After months of debate over lodging tax funds, the council voted 4-3 to award the popular aviation event $20,000.

Logo for news use featuring the municipality of Stanwood in Snohomish County, Washington. 220118
Stanwood jail costs expected to exceed budget by end of 2025

As of September, the Stanwood police has spent $53,078 of its $59,482 annual jail budget.

Alex Waggoner is handcuffed after being sentenced to 19 years for the murder of Abdulkadir Shariif Gedi on Wednesday, Sept. 17, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Edmonds man sentenced to more than 19 years for death of rideshare driver

Judge Richard Okrent sentenced Alex Waggoner, 23, Wednesday after a jury earlier found him guilty of murder in the 2nd degree.

Snohomish County Sheriff's Office K-9 vehicle along U.S. 2 where a man was shot on Wednesday, Sep. 17, 2025, in Sultan, Washington. (Snohomish County Sheriff's Office)
Suspect arrested in King County after person shot near Sultan along US 2

The assault investigation closed down east and westbound lanes of U.S. 2 Wednesday afternoon.

The Rimrock Retreat Fire burned through the Oak Creek drainage in Yakima County in 2024, but the damage was minimal due to tree thinning and prescribed burns the Department of Natural Resources completed in the area with House Bill 1168 funding before the fire. (Emily Fitzgerald/Washington State Standard)
Lands commissioner wants $100M boost for wildfire funding

Washington’s public lands commissioner is asking the Legislature for roughly $100 million… Continue reading

A person walks past the freshly painted exterior of the Everett Historic Theatre on Sept. 24, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Historic Everett Theatre reopens with a new look and a new owner

After a three-month closure, the venue’s new owner aims to keep the building as a cultural hub for Everett.

Local colleges see fewer international students as fall quarter begins

Edmonds College saw a 25% decrease in new international student enrollment, citing visa appointment difficulties.

Cutting the ribbon to celebrate recent upgrades at the Sultan Wastewater Treatment Plant on Sept. 24. (Provided photo)
Sultan celebrates new park and treatment plant upgrades

Two ribbon-cuttings occurred with the community and elected officials from the city, county and state.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.