• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

MSN Encryption

Matty2d

Weaksauce
Joined
Mar 30, 2003
Messages
83
HI i'm using the packet sniffer program Ethreal to sniff out my LAN (This is mainly for admin practise). I notice on a MSN connection or request (Using the MSNMS Protocol)
what i'am initally sending looks like this:

Code:
VER 79 MSNP11 MSNP10 CVR0

CVR 80 0x0409 winnt 5.1 i386 MSNMSGRBETA 7.0.0425 msmsgs [email]msnmessengeraccount@hotmail.com[/email]

USR 81 TWN I [email]msnmessengeraccount@hotmail.com[/email]

USR 82 TWN S t=5gzMC!uyyB6jEdDuw5vAatCdI9Ak!hwmxzSoLGj4uDS*WXorsAB!224gq9CQvT*CxvIub1dCOX*3hUhjs50ZjFew$$&p=50fOiwHg4Gqi4EYM*SRIyrkbQlxUG2CJmbRmioqspN*5GshxfueWgeKXYVubIu& #33;N3sn9iKfCURIV2X7l55DCSzrgOaTDh2UkAFhxxNfxVi6XHckhtpEjjdEFJRn1NC0wlfZ6Sms6uQ8
Uec32sK2qT2aKA35F8gEwNeOk4MgyJUx9XjqYeAGjPWBLaVFANzBZGb0Jh0XZuOCoYxRI5XVatKVg$$

SYN 83 74 0

CHG 84 NLN 1073795180 %3Cmsnobj%20Creator%3D%msnmessengeraccount%40hotmail.com%22%20Size%3D%2225972%22%20Type%3D%223%22%20Location%3D%22TFR79.dat%22%20Friendly%3D%22AAA%3D%22%20SHA1D%3D%22%2FPTtQ1yeaIgbmiNLTu%2FZ0rg09Jw%3D%22%20SHA1C%3D%226UrTDp71Nn4hse%2B5uphcAUqxwBQ%3D%22%2F%3E

XFR 85 SB

QRY 86 PROD0090YUAUV{2B 32

0f265be822364df5577c12b3ba7e1e38

I was wondering since the MSN username is being sent
(in this case - USR 81 TWN I msnmessengeraccount@hotmail.com )
is the password also being somewhere in this request?

I'am assuming it is USR 82 but it is encrypted, if so what kind
of encryption is it. Or am' i totally off?


Thanks
[]v[]atty-D
 
i would assume it was too.

Im curious as to why u need to know what kind of encryption its useing? I would be rather anoyed if i found out the network admin was trying to get my e-mail password without reason
 
Back
Top