Yahoo Protocol 15 Login

Sulabh Mahajan sulabh.dev at gmail.com
Tue Jul 1 06:09:22 EDT 2008


The SSL data that you see is a part of webmessenger login procedure. We do
the same over http, when try to connect using webmessenger to obtain
cookies.

I have never used the webmessenger login method in pidgin, so cant really
tell you for sure.
Maybe someone else can help.

Sulabh

On Tue, Jul 1, 2008 at 2:06 PM, Sanjay Raghani <sanjay.raghani at gmail.com>
wrote:

> Hi,
>
> During the login sequence, Yahoo 8 (YMSG 15) client contacts the server
> login.yahoo.com. It obtains token from the server on this connection and
> later sends it to the yahoo server on port 5050.
>
> Some user documented it in detail at the following link
>
> http://www.xssed.com/article/14/Paper_In-Depth_Analysis_of_Yahoo_Authentication_Schemes/
>
> In the login traces of Yahoo 8 client i could see it establishing a
> connection with login.yahoo.com (it goes over SSL) but pidgin client
> doesnt establish connection with login.yahoo.com.
>
> Thanks
> Sanjay Raghani
>
>
> On Tue, Jul 1, 2008 at 1:39 PM, Sulabh Mahajan <sulabh.dev at gmail.com>
> wrote:
>
>> Yahoo Messenger 9 uses YMSG 16, we don't support the login sequence it
>> uses. I will be working on it, after my GSoC project is over, if no one else
>> does it by then. :)
>> Sooner or later version 16 login process will be done.
>>
>> Pidgin uses the same login process as yahoo 8.1, we still support old
>> login process, though I don't think its used anymore.
>> We can also use web messenger login type, though its turned off by
>> default.
>>
>> Can you tell me what difference you found in the login process of pidgin
>> and yahoo 8.1.
>>
>> Depending upon your firewall settings and connection preferences, YMSG
>> data might be sent to one of several ports yahoo server supports, like HTTP,
>> even telnet.
>> This might change the way the login process appears on a packet sniffer,
>> like wireshark doesn't recognize the data as YMSG when sent to port 23.
>> We only send to port 5050.
>>
>>
>> Sulabh
>>
>> 2008/7/1 Sanjay Raghani <sanjay.raghani at gmail.com>:
>>
>>>  Hi,
>>>
>>> Pidgin 2.4.2 client implements Yahoo Protocol Version 15 (Yahoo 8.1.0.402
>>> client). However the login protocol used by Pidigin is different than that
>>> used by Yahoo 8.1 clients. Pidgin 2.4.2 seem to be using older login
>>> protocol.
>>>
>>> Please correct me if it is not the case.
>>>
>>> Further i would like to know that is there some work currently being done
>>> to implement/support the newer login protocol of for Yahoo?
>>>
>>> Also the newer Yahoo 9 version (which is still in beta) has different
>>> login sequence in comparison to even the Yahoo 8 (version 15).
>>>
>>> Regards
>>> Sanjay
>>>
>>> _______________________________________________
>>> Devel mailing list
>>> Devel at pidgin.im
>>> http://pidgin.im/cgi-bin/mailman/listinfo/devel
>>>
>>>
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://pidgin.im/pipermail/devel/attachments/20080701/e95bdb0a/attachment.html>


More information about the Devel mailing list