Security Basics mailing list archives

Re: Private IP address with yahoo messenger


From: Alcides <alcides.hercules () gmail com>
Date: Thu, 24 May 2007 16:10:46 +0530

Hi Vivek,
Thanks for your attention.
Sorry, but I think it's not something I was expecting for.

In my question, by saying "chat session" - I mean just a "chat session". No file transfer/ video/ voice chat. Simply typing the text in chat window.

[I]a <-------->Yahoo server(s) <-------> b[target]

A thing that comes in my mind is something that may allow me to do thorough forensic analysis of the packets coming from target. But I'm not very sure on what tool/s to be used and about the technique.

Hope I've made my question clear.
Warm regards.

Vivek P wrote:
Hi

I had been testing on this for quiet some time now. In versions of
yahoo messenger before 6, when i transfer a file >2 mb and try netstat
-a -n from CMD on windows machine, i was able to get the IP address
(internal) of the person at the other end !!

Yahoo did some patches in the latest editions but, i have been
informed by my testing team that burp proxy can get the target IP
(internal) if you have it installed, when using latest edition to do
file transfer,

Also when you do calls using messenger point to point connection is made.

it is like

normal chat
a <-------->Yahoo server(s) <-------> b

Lengthy processes (filetransfer) (calls) etc.
a<------->Yahoo authenticates at interval<----->b
a<------->b //Direct connection.


I think it would help, please revert so that i can get you some video
demonstations to prove my experiment.


Thanx


Current thread: