TeamSpeak 2 Security Issues

Asphyxia

Owner
Administrator
Apr 25, 2015
1,845
2
2,199
327
In this video I step back in time to TeamSpeak 2:
"TeamSpeak 3 vs TeamSpeak 2"

The reason I am bringing this up is because history CAN repeat itself. If we pull up old security issues, we may find the same ones in TeamSpeak 3.

Here is a list of issues with TeamSpeak 2 I remember.
  1. You could make your client name disappear by creating a channel, then renaming yourself the channel name quickly.
  2. Creating a channel with "{\rtfobjlink\lol" will throw error, there was a way to crash clients with this but they patched it because of the abuse.
  3. You could hex edit your client to add on a nullbyte to the end of your nickname, which would crash anyone that clicked on you.
  4. Using Hydra to brute-force into server admin accounts was easy.
  5. Creating a bunch of channels with "www.www.www." repeating inside the description would cause any connecting users to time out immediately.
  6. "Right click my name and type echo." --- If you tricked a server admin to do this, you would be granted server admin rights. This was a common social engineer method.
  7. You could lure people into your server, then grant them registration rights. They would sign up with a username and password. Their username and password is written in plain-text to a database. This could be used to compromise emails and other accounts where the user has same or similar passwords. ;)
There were many others, these are just some I can recall. Anyone else have TeamSpeak 2 security issues/exploits they know of?

I found this to be a funny quote:
Greetings TeamSpeak community!

We have released a new version of the TeamSpeak 2 Server. Version 2.0.23.19 contains numerous security patches, including a hotfix which patches a recently discovered exploit which could allow an attacker to read files on the local hard disk where the TeamSpeak server is installed. We urge you to update your server binary files as quickly as possible. Downloads are available from our Downloads page.

In most cases if you are using a recent version of the server, you will only need to download and replace the "Updated Executable" for your relative operating system. However, a full distribution package for 2.0.23.19 is also available.
Source: http://forum.teamspeak.com/threads/...-23-19-with-Security-Patches-is-Now-Available
 
Last edited:
Top