Yahoo Messenger Security Alert!




Recently it was discovered that Yahoo! Instant Messenger version 5.x has a security issue in some cases. This effects nearly all 5.x versions up to and including the current one offered. It is possible it may be posting IP addresses openly in rooms that may be read in some cases with older messenger versions and/or clients. I am not a Yahoo Messenger user really. I have it but I certainly am not a big user. So I rely on others I know for their know how when it comes to this program. Below you will find a link to NHYRVANA's Messenger Information.

link to http://www.nhyrvana.com/mess_5.html
screen shot from and link to www.nhyrvana.com/mess_5.html page.

For this reason and until this problem has been corrected if you are a user of Yahoo Messenger, I would strongly recommend you find an older version of Messenger such as 4.1.0.997 or other 4.1.0.9xx version and use that until this hole has been plugged or refrain from using the software. This is a MAJOR security concern when your IP address is posted openly in chat. With or without a firewall it is not safe to openly display your IP address in chat. Unless you are using a very effective annomizing proxy server and that is the IP address displayed, you are subject to attempted connections, forced downloads and other serious attacks to your computer systems security.

Here is a download link to
Yahoo Messenger 4.1.0.997 and 4.1.0.967
in zip format. ( requires Winzip or other program to install.



Uninstall the current version of Yahoo Messenger from the control panel ( start, settings, control panel - add/remove programs ) then unzip and run the install file in the zipped version you downloaded above. You may get a screen when you log on asking if you wish to upgrade to the newer messenger versions to which reply NO at least until Yahoo patches this very serious hole in the Messenger program.


Later Update... The later versions on this Instant Messenger are somewhat more secure however they are still very subject to PM bombs and other hack attempts. You should keep your PM listings set to friends only if for no other reason to avoid the spam bots that will bombard you with URLs generally to porno sites.



Close This Browser Window





2-06-2002