There’s something going on with AIM as described here and here, and as I saw firsthand:
(13:47:52) UnstoppableCoho: Happy Birfday!
(13:49:47) poppylinden: thanks!
(13:49:50) poppylinden: who is this?
(13:51:05) UnstoppableCoho: hello
(13:51:55) poppylinden: hi!
(13:52:15) UnstoppableCoho: who is this?
(13:52:27) poppylinden: you should know, you messaged me.
(13:52:39) poppylinden: is this you? http://forever-alone.livejournal.com/1104468.html
(13:53:12) UnstoppableCoho: definitely not
(13:53:30) poppylinden: what screen name does AIM say I have?
(13:53:45) UnstoppableCoho: pulsingcoho
(13:53:50) UnstoppableCoho: you mesaged me
(13:53:55) poppylinden: interesting, that is not my sn
(13:53:56) UnstoppableCoho: maybe its an AIM fluke
(13:54:09) poppylinden: sounds like someone’s got an exploit out there
(13:54:19) poppylinden: that sends the initial message
(13:54:37) poppylinden: are you in the USA?
(13:54:38) UnstoppableCoho: well, have a great day.
(13:55:02) poppylinden: i’m going to try to figure this out and report it to AIM
(13:55:36) poppylinden: but it’d help to know how you’re on the internet – at home? at work? at a cafe?
(13:56:48) poppylinden: you there?
Anyone familiar with the AIM protocol have any idea what the bug / exploit is that sent the initial message?
2008-11-17 at 15:32 (15) |
I opened a sec ticket already, let’s see what happens…
2008-11-17 at 16:40 (16) |
I’ve seen this, but not nearly as fun, and with the same AIM SN.
2008-11-17 at 19:17 (19) |
Hey, after reading about your experience with unstoppablecoho, I decided to do some more research and I think I’ve figured out what’s really going on. It’s a bot called TheGreatHatsby.
I’ve compiled all the links here: http://blog.metamorphium.com/2008/11/17/aim-bug-mystery-solved/
2008-11-18 at 14:39 (14) |
So it appears this is *literally* just a bot army. I can’t imagine someone wasting time / CPU on this, that’s why that didn’t occur to me that it was just an echo chamber.