America Online Exploits Bug in Own Software (1999)
geoffchappell.com
geoffchappell.com
https://slashdot.org/story/01/01/25/1343218/directvs-secret-...
The guy telling me this story had some credibility from his work history; and an astounding collection of candid amateur porn and "famous people data". Every journalist used SideKick to keep their contacts, apparently. Fun times.
There were persistent stories, then; that AOL officially scraped clients for addresses to send "free Trial" disks to. Those were officially denied. They carefully didn't talk about what employees might be able to access "on their own" and didn't ask much about where their "prospect" mailing lists came from, either.
They were very eager to buy lists at less than the going rate that were better than random. Later they got less selective, modems could be assumed. Then about the time Win 3.1 happened they got truly spammy.
Since the client code we wrote only talked to the server code we also wrote, the security standards were a bit looser. Host code would never have a bug like this; the host side was constantly attacked by hostile clients and just routers that bit flipped in weird places; overflow bugs would have happened and would have triggered a crash, core dump, and bug fix right away. But the client team was a lot more product / feature driven and constantly rushing.
If someone had stood up an alternative host endpoint then this would have been a bigger issue, but I think the attacks were only other clients logging into our hosts. Tho there is now a group trying to recreate the host complex I have heard.
We did patch the bug and replace the buffer overflow with a new “send us the checksum or hash or this range of virtual memory” which was as good for stopping attacks. They could have shifted to a client that ran the real client invisibly and controlled it thru windows API but they didn’t
As far as legitimate goes, I think it was soon rendered against the TOS of the person logging in, tho I don’t find TOS to be a particularly useful concept or practice.
Microsoft also gave away http clients and http servers and it cost humanity a lot (for a while) that those attacks succeeded.
Now google is attacking by again giving away free software and using their monopoly money to attack competitors.
And for the ads, development keep an arbitrary 64k limit on ad sizes so they couldn’t be giant multimedia monstrosities.
I always use we when talking about this job because it was a good group of very smart developers that I learned a lot from, not because I personally merit the reflected glory.
Out of interest, Geoff Chappell is the same man who uncovered one of Microsoft's dirtiest tricks: https://en.wikipedia.org/wiki/AARD_code
I like modifying future versions of the client to produce similarly useful behaviour deliberately though, seems like a reasonable "apply evil hack, turn into less evil hack as soon as possible" sort of approach to the situation.
Famous line.
I suspect if this sentence was written today, the author would not mention the download was free. In fact, they would only mention the price if the download wasn't free.
It's an interesting change in expectation where in the 90s there was far more of an acceptance/expectation to paying for software as compared to today. I suspect Google changed expectations with Gmail (it provided an order of magnitude more storage for free compared to paid email providers), but that's only a guess. I would be interested in learning more about how the consumer expectation changed over time.
Oh, they definitely did – I used it myself.
I think these shenanigans were mainly to counter 3rd parties from connecting to AIM. MSN tried to very briefly, I think, but AOL attacked GAIM (now called Pidgin) consistently for years.
JOOI: the author of the piece is the same person who uncovered Microsoft's AARD code that made Windows 3.1 fake failing on DR-DOS.
We didn’t feel it was bad to buffer overflow our own code, since it was client code we wrote in the first place. Later client versions had some sort of “checksum this range of virtual memory and return the checksum” and the buffer overflow fixed.
As far as GAIM the dev team didn’t care about that, and efforts to stop it were pretty much half hearted, if I recall. We ended up hosting an end point “toc.oscar.aol.com” to let things like the TCL client and the elisp client work. We couldn’t convince people to release the protocol specs for the full Oscar protocol unfortunately.