main

MSN Messenger 7 Beta News - no winks, no sign-in

Tom Warren   on 06 October 2004 - 17:03 · 141 comments & 55146 views

Advertisement (Why?)
Following on from our security alert this week MSN have not only delayed the release of an external beta but they're planning to remove crucial new features temporarily. According to sources close to MSN, MSN Messenger 7 beta will ship without 'winks' and deluxe display pictures. Currently it's easy for hackers to exploit the code of winks to display any flash movies on a users computer for any amount of time.

MSN took the decision following the public announcements of the exploits. We're unsure whether 'winks' are going to be axed from MSN Messenger 7 or whether MSN are merely revamping them to be included in later betas.

In other news, The Messenger team will be implementing a CVR update that will force all existing MSN Messenger V7.0 users to downgrade to V6.2. This CVR is scheduled to start on 6 Oct 2004. Anyone running MSN Messenger V7.0 build 0205 will need to downgrade. If you do not downgrade, you will be unable to sign into the Messenger service. We're unsure whether this will effect other builds.

News source: In-House


The Mydoom.m variant that appeared in August hung on to fifth place with the same occurrence rating. The main newcomers this month are two Mydoom variants that appeared in the space of a single day. Bagle authors were not caught napping and brought their summer holidays to a close by releasing several new variants, which all used email and file-sharing networks to spread. TrojanDownloader.JS.Gen is a catch all name for a huge number of Trojans written in Java Script.

We group them together because they all have only one function - to download other malware from the Internet. This summer virus coders were placing such Trojans on websites, wheras in September we saw a new trend: using spammer techniques to mass mail malicious programs. On the one hand, Bagle, LovGate and NetSky variants carry on creating a steady background of virus activity, moving insignificantly up and down in the ratings.

On the other hand, the old steadfasts Swen and Sobig.f have finally disappeared from the Top Twenty. In other words, September 2004 finally saw malware created in previous years vanish totally from the ratings: we now have only viruses created in 2004. Moreover, 16 out of 20 viruses in this month's Top Twenty are worms from only three families. The only serious competion Bagle, NetSky and Mydoom variants face comes from Zafi and Lovgate.


1 +3 I-Worm.NetSky.q 21.67
2 -1 I-Worm.NetSky.aa 13.79
3 +1 I-Worm.Zafi.b 12.70
4 -2 I-Worm.NetSky.b 9.63
5 - I-Worm.Mydoom.m 5.34
6 +2 I-Worm.Bagle.z 4.86
7 +2 I-Worm.NetSky.d 4.55
8 New TrojanDownloader.JS.Gen 4.41
9 -3 I-Worm.NetSky.t 2.51
10 +1 I-Worm.NetSky.y 1.62
11 -1 I-Worm.LovGate.w 1.41
12 New I-Worm.Bagle.as 1.35
13 +2 I-Worm.Mydoom.l 1.11
14 -2 I-Worm.NetSky.r 1.08
15 New I-Worm.Mydoom.t 0.93
16 +3 I-Worm.Bagle.gen 0.86
17 Re-entry I-Worm.NetSky.c 0.83
18 -5 TrojanDropper.VBS.Zerolin 0.73
19 New I-Worm.Bagle.ah 0.62
20 New I-Worm.Mydoom.u 0.51
Other malicious programs 9.50

Post a comment · Send to friend Comments · There are 141 additional comments
#1 WinMacLin on 06 Oct 2004 - 17:07
hahahha
#2 AngelicRaver on 06 Oct 2004 - 17:08
OH! BURN! All those patches and the MSNplus combatible for 7 that are coming out will be for nothing. *laughs*
(8 replies) #3 RaccoonSalsa on 06 Oct 2004 - 17:08
i don't want to downgrade, not fare
#3.1 WindowsNT on 06 Oct 2004 - 17:11
life isnt fair

also MSN have every right to do this if there are security issues, it's there software and there network.
#3.2 AngelicRaver on 06 Oct 2004 - 17:14
Yep, ya'll really didnt have a right in the first place to install it It wasnt even meant to see the light of day yet. So stop compaining and use the build that is stable.. skinible.. upgradible.. O.o you know 10x better then 7 as of now?
#3.3 WindowsNT on 06 Oct 2004 - 17:20
that's very true, i'm happy with 6.2 and cant see why ppl want to be "cool" and use an unfinished product. If your an Official MSN Beta tester that's fine.

The whole idea of Beta testing is to HELP the vendor, so if your not helping the vendor quit complaining
#3.4 cheesegoduk on 06 Oct 2004 - 19:12
QUOTE
it's there software and there network

and its MY pc
#3.5 Alegis on 06 Oct 2004 - 19:22
So? If you disagree with

it's their software and their network

then just don't install it/use it. It's that simple.
You can't steal an apple, put it in your house and later say: "NO, ITS MY HOUSE so you dont get it back"
#3.6 kitchenutensils on 06 Oct 2004 - 19:23
lol i hear u - and i its entirely their decision... but 7.0 is lovely compared to 6.2. sooner they stop it the better!
#3.7 configure on 06 Oct 2004 - 19:24
QUOTE
and its MY pc

What kind of logic is that? You can do whatever you want with your PC but don't be claiming "it's my PC, it's my PC" when you can't sign in because it is their network.
#3.8 bangbang023 on 06 Oct 2004 - 20:23
QUOTE
and its MY pc

And they are't forcing you to uninstall it. You can keep it on there as long as you want. You jus twon't be able to use their network resources if you so choose to.
#4 longwilli on 06 Oct 2004 - 17:09
is there any point in having a 7 if it doesn't have these features? i would rather wait then have a needless release.
(3 replies) #5 Cryptic_Night on 06 Oct 2004 - 17:12
Problems: I have sent this to some of my friends and I'm not sure they wil know how to downgrade. I better start telling people.
#5.1 Miran on 06 Oct 2004 - 17:34
You sent an unofficial early beta to friends who won't know how to downgrade? How stupid can you get?
#5.2 kronik on 06 Oct 2004 - 18:19
lol @ your irresponsibility
#5.3 Mav Phoenix on 06 Oct 2004 - 23:50
So true, noob at work.
(4 replies) #6 Siebe on 06 Oct 2004 - 17:15
*cough* Hex edit or use a proxy (Or even use your Hosts file) that changes the CVR command (Well documented on Hypothetic, easy to change, too) and voila. Pretend you are MSN Messenger 6
#6.1 kitchenutensils on 06 Oct 2004 - 21:41
right explain how to do that and ill be doing it faster than u know.
#6.2 stezo2k on 06 Oct 2004 - 21:48
hope your right....
#6.3 Geo on 07 Oct 2004 - 02:35
is the this same bragging guy ?
#6.4 Siebe on 07 Oct 2004 - 16:26
Sure, I'm the "bragging" guy now, amnt I. At least I can "prove" it works.. And yes, Inky is me. Oh wait, was that bragging?

Edit: Removed the link myself *points at posts down the road*. It's on the Mess.be forum, anyhow (Under "MSN Messenger".
#7 XanoZuke on 06 Oct 2004 - 17:16
Hell, oh well.
#8 M2Ys4U on 06 Oct 2004 - 17:17
It should tell them to downgrade
#9 The_Decryptor on 06 Oct 2004 - 17:17
Awww, and i only just started making my winks
#10 The Napster on 06 Oct 2004 - 17:18
Damn, and i just installed MSN Messneger 7 Beta
O well
(2 replies) #11 whistlerxp on 06 Oct 2004 - 17:25
Ah crud, and I was looking forward to custom winks saying "NEVER SEND ME WINKS AGAIN"
#11.1 The Napster on 06 Oct 2004 - 17:26
LOL
#11.2 The_Decryptor on 06 Oct 2004 - 17:28
Yeah, you could do that, or everytime they send you a wink, you send a rude one back

Or, just send a wink that blocks all the other winks (like timothy's or mine)
(4 replies) #12 Frash on 06 Oct 2004 - 17:47
What a bull****, Flash's actionscript is just as powerfull as javascript, a widely used web language.
Flash sigs would be dangerous too then. OMG Its an alert window, now my meguhurtz will be stoeled!111one
#12.1 Sub on 06 Oct 2004 - 17:50
<removed neowin option to display flash sigs>
#12.2 The_Decryptor on 06 Oct 2004 - 17:55
Becuase, when flash is running in a browser, it's secured, it cant do anything bad

When it's running in messenger7 (just msn7, ms forgot to secure it), it's unsecured, it can read and write to the file system
#12.3 Frash on 06 Oct 2004 - 18:20
I admit that is dumb indeed... so Flash doesnt have buildin protections?
#12.4 Porp on 06 Oct 2004 - 23:34
Well, in the ThreeDegree's model of Winks they used animated gif's... so I don't see why all of a sudden they changed it to flash? (Even though flash is better)
#13 funkyMonkey on 06 Oct 2004 - 17:49
I didn't even install it. I am getting old and boring.
(2 replies) #14 XP_01 on 06 Oct 2004 - 17:49
hahaha this is great. Microsoft panics every time they have to integrate a new feature into their products.
Delays Delays Delays. I'm Lovin' it
#14.1 The_Decryptor on 06 Oct 2004 - 17:56
Well, would you like to have a program running on your system that allowed peole to send you small programs that have full access to your system.

I know i wouldnt.
#14.2 XP_01 on 06 Oct 2004 - 18:10
I'm also running Windows so I'm kinda used to that fact
It's just so funny that a mayor company like this seems to have huge problems with virtually every new thing they develop. They REALLY didn't knew about this problem before leaking this build???

Last edited by 22885 on 06 Oct 2004 - 19:44
#15 R-Style on 06 Oct 2004 - 18:21
I think soon there will be a patch available that you still can use MSN 7
#16 Lain on 06 Oct 2004 - 18:30
will those features be in it when its officially released and out of beta stages?
#17 GHL on 06 Oct 2004 - 18:33
haha reading into that it seems the delux (animated) display pics were flash too...
#18 Jason on 06 Oct 2004 - 18:38
None of the features that are temporaily removed are anywhere near crucial.
#19 none on 06 Oct 2004 - 18:38
I hate to tell all the people who flamed me before "I told you so", so I'll just say UP-YOURS Sad how some users just HAVE to get hostile when they see someone say something they don't like the sound of about a program... I didn't insult anyone, but everyone just had to insult me... Well yo-ho-hello there, guess some of what I said WAS valid

http://www.neowin.net/forum/index.php?showtopic=225761&st=0
#20 Jugalator on 06 Oct 2004 - 18:43
Heh, at least they did what I said they should do in the last thread

I made it more to joke, but in a way it's good they're taking security so seriously.

You only have to wonder why they didn't see this when it just took a matter of days to discover in the "public beta".
#21 vbagaria on 06 Oct 2004 - 19:25
oh man.. i like 7.. this sucks.. dont wanna go back to 6.2
#22 XP_01 on 06 Oct 2004 - 19:46
Wednesday, October 6, 2004 9:46 PM CEST - Amsterdam, The Netherlands
MSN Messenger 7 build 205 is still operating within normal parameters
(2 replies) #23 ynohtna on 06 Oct 2004 - 19:46
I'll miss my ability to sign in as offline!!!
#23.1 AngelicRaver on 06 Oct 2004 - 20:19
Umm.. just use the DiscoveryMessenger add on.

moo
#23.2 ynohtna on 06 Oct 2004 - 21:16
I don't care much for add ons though....
(1 reply) #24 James55 on 06 Oct 2004 - 19:49
The only thing about 6.2 I dont like is the huge message window and 7.0 took care of that. Oh well. Back to the 6.2
#24.1 XP_01 on 06 Oct 2004 - 19:53
uh the MSN Messenger 6 and 7 message windows are identical... (except for the 2 extra buttons). Or am I missing something?
#25 Jedimark on 06 Oct 2004 - 20:14
What does CVR stand for?
#26 Z3r0 on 06 Oct 2004 - 20:30
Current Version Rollback is my guess
#27 )(RockerBoy on 06 Oct 2004 - 20:31
that sucks
#28 slimy on 06 Oct 2004 - 20:35
if it doesn't sign on I'LL MAKE IT sign on
(1 reply) #29 Boogiman on 06 Oct 2004 - 20:36
I'll bet, that when MS goes back to 6.2, half the ppl who are using MSN 7 don't know what happend and don't know what to do to get back on MSN.
#29.1 madd_matt on 06 Oct 2004 - 20:51
dude, anyone with that lack of brains shouldn't be using beta software man
#30 Kushan on 06 Oct 2004 - 20:47
You know it would be cool if M$ exploited thier own exploit in order to uninstall 7 and reinstall 6.2 lol
#31 chouli on 06 Oct 2004 - 20:47
a patch is already avaible but tell me if i can give the link ...if not just search it is very easy to find
(4 replies) #32 Aaron660R on 06 Oct 2004 - 20:53
7.0 still works for me
#32.1 devinlamothe on 06 Oct 2004 - 21:00
Me too. Maybe those of us who used the patches altered the EXE file enough for this trick not to work.
#32.2 Rockett15 on 06 Oct 2004 - 21:08
same
#32.3 Ryan92 on 06 Oct 2004 - 22:30
lolz...They'll get you soon......Mines appears to be downloading the Latest Version of MSN Messenger [BETA] even though I modify the exe heavily
#32.4 fatgirl319 on 07 Oct 2004 - 02:35
where is it????
#33 Dale on 06 Oct 2004 - 20:54
uh, time to go back to Windows Messenger...
(1 reply) #34 SimNet on 06 Oct 2004 - 21:26
yo why dont we all do what someone here Saiba or something said, edit the hosts file, well that's what i want to do... any links to how to do it? (i know how to use the hosts file, but what exactly to change..etc?)

thx
#34.1 Geo on 07 Oct 2004 - 02:40
He talks a lot of ****, you just need to edit the version resource, try Resource Hacker or Resource Tuner. (google it)
#35 ELeVeNtY on 06 Oct 2004 - 21:31
yeh my msn still works
#36 RipeR81 on 06 Oct 2004 - 21:39
who cares about the winks anyways...
#37 Chanser on 06 Oct 2004 - 21:41
Schtop it's not ready yet!
#38 IRazor on 06 Oct 2004 - 21:43
When will it stop working?
#39 allfive6 on 06 Oct 2004 - 21:45
Damnit atleast it is only temporarily.
#40 RipeR81 on 06 Oct 2004 - 21:51
who cares about the winks anyways...
#41 robpears on 06 Oct 2004 - 21:57
lol
#42 sumeet on 06 Oct 2004 - 21:57
my e-peenus just shrunk
(1 reply) #43 RDD on 06 Oct 2004 - 22:23
not working anymore
#43.1 RDD on 07 Oct 2004 - 00:13
Working again (+ Patch)
#44 Rockett15 on 06 Oct 2004 - 22:23
yeah it just did it to me too
#45 y_notm on 06 Oct 2004 - 22:33
well, i just got asked to "upgrade" from msn 7 to msnim 6.2, I'd say this has taken effect.
(2 replies) #46 Chris123NT on 06 Oct 2004 - 22:39
Hehehe reshacker is my friend, got it to sign in again
#46.1 SonDaniel on 06 Oct 2004 - 22:45
good for you
#46.2 aadhu on 06 Oct 2004 - 22:47
aha??????? and how.. i tried a little bit of it didn't really do me any good
#47 SonDaniel on 06 Oct 2004 - 22:43
man

I really like the new MSN, too bad i have to downgrade
#48 dark kyuubi on 06 Oct 2004 - 22:45
lol....I just got downgraded too.....
#49 dl0711 on 06 Oct 2004 - 22:45
Removed

Last edited by 98 on 06 Oct 2004 - 23:10
#50 shadowdawg on 06 Oct 2004 - 22:50
people , install the cvrp and u wont have too duh,and u can still do it while i get the upgrade notice
(1 reply) #51 Droopyboy on 06 Oct 2004 - 22:51
there is a patch on mess.be
#51.1 aadhu on 06 Oct 2004 - 22:55
where?
#52 IRazor on 06 Oct 2004 - 22:53
There's already made a patch to fix the downgrade problem.

I was a bit late