AOL fixes major security hole

By D. Ian Hopper

Associated Press

WASHINGTON – As AOL Time Warner engineers opened their presents and spent time with their families, a team of young hackers planned a holiday surprise: a major security hole in one of the company’s flagship programs.

The international group released a program that turns AOL’s Instant Messenger into a key that could unlock many home computers. Now the hackers are being criticized by security experts for not giving AOL sufficient time to react.

The group, founded by a 19-year-old Utah college student, discovered a security hole in AOL’s Instant Messenger program that could have let a hacker take control of a computer. AOL fixed the problem at its central networks today.

“The issue was resolved early this morning and was handled on the server side, so users do not have to download anything or take any other action,” AOL spokesman Andrew Weinstein said. “To our knowledge, no users were affected by this issue prior to its resolution.”

The problem affected the newest as well as many earlier versions of AOL’s Instant Messenger program, which boasts more than 100 million users.

“You could do just about anything: Delete files on the computer or take over the machine,” said Matt Conover, founder of the hackers’ group, “w00w00.”

Conover said w00w00 has more than 30 active members from 14 states and nine foreign countries.

Conover, who attends Utah State University, said the group found the problem several weeks ago but didn’t contact AOL until after Christmas. The group got no response from AOL to an e-mail sent during the holiday week, he said, so w00w00 released details – and a program that takes advantage of it – to public security mailing lists less than a week later.

The program released by w00w00 remotely shut down a user’s Instant Messenger program but could have been modified to do more sinister things.

That practice is under scrutiny by security professionals. While some independent researchers argue for a “full disclosure” policy and say software vendors are trying to hide their mistakes, many companies say users are better protected if companies have time to react.

“I think that’s pretty dangerous,” said Chris Wysopal of the security company AtStake, “especially since they pretty much acknowledged that they hadn’t gotten a response back from AOL yet.”

Russ Cooper, who moderates a popular security mailing list and works for the security firm TruSecure, said Conover’s action was irresponsible because it helped hackers.

“I think it’s better to provide details of the exploit and then let other people write the actual code,” Cooper said. “It lets the technical community have the information they need without letting idiots have the information they want.”

Conover said w00w00 set a New Year’s deadline for sentimental reasons, because it was the anniversary of the group’s last major security release. He defended the disclosure of the attack program because “it means providing all the information we have available to the security community.”

AOL’s Weinstein said the company would have appreciated more warning.

“We’d encourage any software programmer that discovers a vulnerability to bring it to our attention prior to releasing it,” Weinstein said.

Copyright ©2002 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Olivia Vanni / The Herald 
The Mukilteo Lighthouse. Built in 1906, it’s one of the most iconic landmarks in Snohomish County.
The Mukilteo Lighthouse. Built in 1906, it’s one of the most iconic landmarks in Snohomish County. (Olivia Vanni / The Herald)
Mukilteo mayor vetoes council-approved sales tax

The tax would have helped pay for transportation infrastructure, but was also set to give Mukilteo the highest sales tax rate in the state.

Marysville Mayor Jon Nehring gives the state of the city address at the Marysville Civic Center on Wednesday, Jan. 31, 2024, in Marysville, Washington. (Ryan Berry / The Herald)
Marysville council approves interim middle housing law

The council passed the regulations to prevent a state model code from taking effect by default. It expects to approve final rules by October.

x
State audit takes issue with Edmonds COVID grant monitoring

The audit report covered 2023 and is the third since 2020 that found similar issues with COVID-19 recovery grant documentation.

Bothell
Bothell man pleads guilty to sexual abuse of Marysville middle schoolers

The man allegedly sexually assaulted three students in exchange for vapes and edibles in 2022. His sentencing is set for Aug. 29.

Larsen talks proposed Medicaid cuts during Compass Health stop in Everett

Compass Health plans to open its new behavioral health center in August. Nearly all of the nonprofit’s patients rely on Medicaid.

Snohomish County Health Department Director Dennis Worsham on Tuesday, June 11, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Snohomish County Health Department director tapped as WA health secretary

Dennis Worsham became the first director of the county health department in January 2023. His last day will be July 3.

Police Cmdr. Scott King answers questions about the Flock Safety license plate camera system on Thursday, June 5, 2025 in Mountlake Terrace, Washington. (Olivia Vanni / The Herald)
Mountlake Terrace approves Flock camera system after public pushback

The council approved the $54,000 license plate camera system agreement by a vote of 5-2.

Community members gather for the dedication of the Oso Landslide Memorial following the ten-year remembrance of the slide on Friday, March 22, 2024, at the Oso Landslide Memorial in Oso, Washington. (Ryan Berry / The Herald)
The Daily Herald garners 6 awards from regional journalism competition

The awards recognize the best in journalism from media outlets across Alaska, Idaho, Montana, Oregon and Washington.

x
$14.5M property tax levy lid lift moves forward in Edmonds

After a public hearing, the City Council voted 5-2 to place the resolution on next week’s consent agenda for final approval.

Mikki Burkholder, left, and Sean Seifert pull drafts Friday afternoon at 5 Rights Brewery in Marysville on October 8, 2021. (Kevin Clark / The Herald)
5 Rights celebrates 10 years in Marysville

During a challenging time for the US craft beer industry, 5 Rights continues to enjoy growth and an uptick in sales.

Wine is illuminated on a large win rack at the center of the main room at Long Shadows Woodinville Tasting Room & Key Club Lounge on Friday, Feb. 28, 2025 in Woodinville, Washington. (Olivia Vanni / The Herald)
Two winery restaurants in Woodinville stand out

You wouldn’t expect to get world-class pizza at a winery,… Continue reading

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.