Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
MSN Chat - IRCX (Microsoft компаниясының Internet Relay Chat кеңейтулері) Microsoft Network нұсқасы, ол Microsoft Chat-ты алмастырды, бұл Microsoft Comic Chat клиентімен алғаш рет қол жетімді Exchange негізделген IRCX серверлерінің жиынтығы, бірақ Comic Chat қосылу үшін қажет емес еді.
MSN Chat was the Microsoft Network version of IRCX (Internet Relay Chat extensions by Microsoft), which replaced Microsoft Chat, a set of Exchange based IRCX servers first available in the Microsoft Comic Chat client, although Comic Chat was not required to connect.
Үшінші тараптың қолданбалары
MSN Чат желісінде үшінші тараптың қолданбаларын пайдалануға тыйым салынбаған, бірақ оны қолдаусыз қалды. Үшінші тараптың қолданбалары MSN Чат Басқару сияқты Аутентификация әдістерін қолдануы керек еді. Екінші өзгеріс - бұл Чат басқаруға Клиент пен MSN Чат қызметі арасындағы байланыстарды көпірлеуге мүмкіндік беретін негізгі өзгеріс. Үшінші тараптың ең танымал қосымшалары mIRC, IRC Dominator және Viperbot болды. Скрипттер көбінесе TechGear007 сияқты сайттардан жүктелген.
The use of third party applications on the MSN Chat Network was not prohibited, although it was unsupported. Third party applications were required to use the same Authentication Methods as the MSN Chat Control. The second change was the major part, allowing the Chat Control to bridge the connections between the Client and MSN Chat Service. The most popular third party applications were mIRC, IRC Dominator and Viperbot. Scripts were often downloaded from sites such as TechGear007.
Қақпа күзетшісі
GateKeeper (және оған жақын GateKeeperPassport) аутентификация механизмдері IRCX жобаларында анықталған SASL аутентификация механизмдері болып табылады. MSN Чатта аутентификация енгізілгеннен кейін Gatekeeper - жұртшылық қолдана алатын жалғыз аутентификация әдісі болды. Алғашқы қол алысу кезінде клиент серверге тек 16 байт тақырыпты қамтитын пакет жібереді, ал сервер 128 бит криптографиялық нонспен біріктірілген тақырыппен жауап береді. Ақырында, клиент серверден алынған нонстың 128 биттік криптографиялық хэшін құпия кілтті қолдана отырып жасайды, оны кейіннен аутентификациялау жауабы ретінде бастықтың алдында және 16 байт GUID-дан бұрын жібереді. Пайдаланылған шифрлау хэш-функциясы hmac md5 болды, ал құпия кілт "SRFMKSJANDRESKKC" (кезеңдік сезімтал).
The GateKeeper (and closely related GateKeeperPassport) authentication mechanisms are SASL authentication mechanisms as defined in the IRCX Drafts. After the introduction of authentication on MSN Chat, Gatekeeper was the only authentication method that the public could use. During the initial handshake, the client would send a packet only containing the 16 byte header to the server, and the server would reply with a header, coupled with a 128 bit Cryptographic nonce. Finally, the client would create a 128 bit cryptographic hash of the nonce received from the server using a secret key, sending this as a subsequent authentication reply after the header, and immediately before a 16 byte GUID. The cryptographic hash function used was hmac md5, and the secret key was "SRFMKSJANDRESKKC" (case sensitive).
Қақпа күзетшісін жеңу
GateKeeper аутентификация механизмін ерте жүзеге асыру кіру үшін кедергі тудырмады, өйткені Microsoft жасаған аутентификация API басқа бағдарлама жасаушыларға қол жетімді болды. Біраз уақыттан кейін Microsoft әзірлеушілерге MSN Чат басқару құралына енген API-ді пайдалану / көру мүмкіндігін алып тастады және осы уақыттан бастап Microsoft тек ресми чат басқару құралынан қол жеткізуді қалаған деп сенімді түрде болжауға болады. GateKeeper аутентификациясы WebTV/MSNTV клиентіне пайда болды. Бұл тез арада, қажет болған жағдайда, MSN Чат басқаруын уақытша жүктейтін прокси-серверді құру арқылы қосылуға болатынын түсінді, сервер мен басқару арасында нонс пен хэштерді сервер мен басқару арасында, чат басқаруын жабудан бұрын. Бұл әдістің қиындығы - бұл жиі баяу, жұмыс істемеді немесе Microsoft Internet Explorer немесе MSIE негізделген веб-бақылауларда қолданылатын ActiveX бақылауын талап етуден пайдаланып, бағдарламаларды құлатуы мүмкін. Мүмкін, MSN Чат Басқаруын басқа браузер (мысалы, Netscape Navigator, Firefox және т.б.) қолдана алатын шығар, өйткені Microsoft-тан NPAPI нұсқасы бар. 2002 жылдың шілдесінде zmic деген пайдаланушы MSN Чат Басқаруын кері инженериямен жасап, MSN Чат Басқаруын пайдаланбай-ақ тіркелуге мүмкіндік беретін питон скрипті шығарды. Python скрипті қатесі бар еді, бірақ кейіннен әртүрлі авторлар бірнеше бағдарламалау тілдерінде қайта жазды. eXonyte пайдаланушысы Linux-та (WINE арқылы) қолдануға болатын код жазды. Бұл MSN Чатты Windows-тан тыс жерде алғаш рет қолданған деп есептеледі. GateKeeper 3-ші нұсқасы енгізілген кезде, бұл өте кішігірім өзгеріс болды, ол хэшке сервердің атауының тізбесін (Сатты басқару параметрі "Серверде" анықталғандай) қосты. Қосымша тізбекке екі нүкте немесе порт қосылмас еді, егер олар болса. Бұл сервиске кірудің прокси әдісін жеңу үшін жасалған әрекет болып көрінді, бірақ пайдаланушылар IP хэшке қосылғаны туралы ақпаратты бөліскенде тез жеңілді. Бұл ақпарат Microsoft-тағы біреуден ағып кеткен болуы мүмкін, өйткені жаңа GateKeeper нұсқасы шығарылғанға дейін алдағы өзгерістер туралы аңыздар болды. 2018 жылы ғана пайдаланушы JD zmic-тің кері инженериясынан алынған түрлі кілттер басқа кілттің туындылары екенін байқады және ол қолданылған алгоритмді таба алмай тұрып жай мәтін кілтін таба алды. Бұл ақпаратты Sky-мен бөліскеннен кейін олар криптографиялық хэш-функцияның HMAC MD5 екенін тез анықтады. GateKeeper аутентификация тақырыбында әлі екі байт белгісіз, бірақ ол MSN Чат серверіне қарсы бірнеше рет сыналды, ал сервер осы екі байттың мәндерін ажырата алмады. Мүмкін, бұл екі байт кездейсоқ жад байттары болуы мүмкін.
Early implementations of the GateKeeper authentication mechanism did not create a barrier to entry, as the authentication API that Microsoft had created was available to other program developers. After some time, Microsoft removed the ability for developers to use/see the API that had been embedded in the MSN Chat Control, and it can be safely assumed from this time that Microsoft wanted access to be from the official chat control only. The GateKeeper authentication made an appearance in the WebTV/MSNTV client. It was quickly realised that it was also possible to connect by creating a proxy that would load the MSN Chat Control temporarily as required, relaying nonce and hashes between the server and control, before closing the chat control. The difficulty with this method is that it was often slow, didn't work, or could crash applications due to requiring the ActiveX control to be used in Microsoft Internet Explorer, or MSIE based web controls. It is likely possibly that an alternative browser (such as Netscape Navigator, Firefox, etc) could have been used to host the MSN Chat Control, as there was a NPAPI version available from Microsoft. In July 2002, a user named zmic reverse engineered the MSN Chat Control, and produced a python script that was able to login without the use of the MSN Chat Control. The python script was buggy, but was later re written in multiple programming languages by various authors. The user eXonyte had written some code which could be used (via WINE) on Linux. It's believed that this was the first time MSN Chat had been used outside of Windows. When GateKeeper version 3 was introduced, it was a very minor change that had added the string of the server name (as defined in the Chat Control parameter "Server") to the hash. The additional string would not include a colon or port if they were present. This appeared to be an effort to defeat the proxy method of accessing the service, but was quickly overcome as users shared the information that the IP had been added to the hash. This information was likely leaked from someone in Microsoft, as there were rumours of the upcoming change before the new GateKeeper version was released. It wasn't until around 2018 that the user JD noticed that the various keys from zmic's reverse engineering were likely derivatives of another key, and he was able to find the plain text key before finding the algorithm used. Upon sharing this information with Sky, they quickly discovered the underlying cryptographic hash function was HMAC MD5. There are still just two bytes that are unknown in the GateKeeper authentication header, however it was tested against the MSN Chat Server many times, and the server didn't appear to differentiate between the values of those two bytes. There's a possibility that the two bytes are random bytes of memory.
NTLM
GateKeeper сияқты NTLM және NTLMPassport IRCX протоколында анықталған SASL аутентификация механизмдері ретінде іске асырылды. NTLM аутентификациясы MSN Чат Басқаруында қолданылмайды, және клиенттің жалғыз белгілі іске асырылуы MSN Чат Әкімшілік Клиентте, бұл MSN Чат қызметкерлері үшін пайдаланылатын, жалпыға қол жетімді MS Чат 2.5 нұсқасына негізделген өте қарапайым клиент. NTLM анықтамалары қарапайым пайдаланушыларға қол жетімді емес еді. MSN Chat қызметкерлері NTLM-ді аутентификациялау үшін қолданды және олар Microsoft-тың Active Directory арқылы аутентификациялады деп есептеледі. MSN Chat қызметкерлері Microsoft желісіне тікелей қосылған болуы мүмкін, немесе виртуалды жеке желі (VPN) арқылы қосылған болуы мүмкін. MSN Chat қызметкерлері RFC 1459 құжаттамасында көрсетілген қауіпсіздігі төмен USER/PASS әдісі арқылы кіруге мүмкіндік алды. Бұл SASL аутентификация механизмдерін білуді қажет етпегендіктен, ресми чат-боттармен көп қолданылады.
Like GateKeeper, NTLM and NTLMPassport were implemented as SASL authentication mechanisms as defined in the IRCX protocol. NTLM Authentication was not available to be used by the MSN Chat Control, and the only known client implementation is in the MSN Chat Admin Client, which is a very basic client that was created to be used by MSN Chat staff, based on the publicly available MS Chat version 2.5. NTLM credentials were not available to normal users. It is believed that MSN Chat staff used NTLM to authenticate, and that they authenticated through Microsoft's Active Directory. It is possible that MSN Chat staff were connected directly to Microsoft's network, or connected via a virtual private network (VPN). MSN Chat staff also had the ability to login via the less secure USER/PASS method documented in RFC 1459. This was used heavily with the official chat bots, as it required no knowledge of SASL authentication mechanisms.
Ұқсас қызметтер
Microsoft Network ұсынған қызметті симуляциялауға тырысатын көптеген чат желілері бар, олар "MSN Чат Басқаруын" қолданады. Бұл симуляциялық чат желілері көбінесе "MSN Чат Клондары" деп аталады. Бұл әдетте шағын чат желілері, олар көбінесе үйде жасалған IRC серверлеріне немесе IRCX серверлеріне сүйенеді. "MSN Чат Клондары" көпшілігі сәйкес келмейді және RFC 1459 (IRC) немесе "eXtensions to Internet Relay Chat" (IRCX) стандарттарына сәйкес келмейді және көбінесе MSN Чат Басқарумен қызмет көрсетуден бас тартуға әкелетін көптеген қателер / эксплойттар бар. MSN-дің көптеген чат-клондары MSN өз қызметтерін тоқтатқаннан кейін (2006 жылы) тікелей басталды, содан бері қосымша желілер пайда болды. Бұл чат желілері мүмкін абоненттерді MSN Chat-тан алып тастаған, нәтижесінде MSN Subscription Chat Services-тің жойылуына әкелген болуы мүмкін деген болжамдар бар. MSN Clone Chat сайттарының көпшілігі тегін болса да, олардың көпшілігі жарнамаларға сүйеніп, аздап табыс табады. Сонымен қатар, кейбір клондар төлемдерді немесе сыйға тартуды талап ете бастады. MSN Чат-бақылауын ұсынатын сайттардың заңдылығы бірнеше уақыттан бері сұраққа ұшырап келеді, себебі көптеген "клондар" сайттары Чат-бақылауды ұсынады. Чат басқаруын жүктеу үшін Microsoft-тың жалпыға қолжетімді нұсқасы мына жерден жүктеледі .
There are many chat networks attempting to simulate the service that was provided by the Microsoft Network, which use the "MSN Chat Control". These simulation chat networks are often referred to as "MSN Chat Clones". These are generally small chat networks, which often rely on home made IRC servers, or IRCX servers. Many of the "MSN Chat Clones" are non compliant and do not follow the RFC 1459 (IRC) or the "eXtensions to Internet Relay Chat" (IRCX) standards and often contain many bugs/exploits that may cause a denial of service with the MSN Chat Control. Many of the MSN Chat Clones started up directly after MSN closed its services (2006), and additional networks have continued to spring up since then. There is speculation that these chat networks may have pulled potential subscribers away from MSN Chat, ultimately bringing on the demise of MSN Subscription Chat Services. While the majority of MSN Clone Chat sites are free, most of them rely on adverts to provide a small income. In addition, some of the clones have begun to charge, or allow for donations. The legality of sites offering the MSN Chat Control has been in question for some time due to many "Clone Sites" hosting the Chat Control. The Chat Control download is publicly available by Microsoft to download at .
MSN чаттағы проблемалар
MSN чат функциясы туралы пайдаланушылардың көптеген проблемалары бар. Көпшілігі "шахтер" жүргізушісіне бағытталды. Бұл "шахтер" деген атпен чат-бөлмеге кіретін және бөлмені реттеу үшін әрекет ететін адам болды. Бұл қызмет бөлмені бақылауға, барлық адамдардың тиісті түрде әрекет етіп жатқанына көз жеткізуге, пайдаланушылардың бөлме туралы сұрақтарына жауап беруге және басқа да түрлі тапсырмаларға пайдалы болды. Бақылаушы идеясы көптеген пайдаланушыларды ыңғайлы ете алса да, екеуінің арасында орынды деп саналатын нәрсеге келіспеушіліктер болған. Бірде, көптеген ереже бар екендігі айтылды, бірақ қонақ үй иесі пайдаланушыларға түсіндіруді ұсынбады, сондықтан көптеген адамдар өздері білмейтін ережелерді бұзғаны үшін бөлмеден шығарылды. Ондай мақалалар бірден алынып тасталды, ал оларды жазған адам бөлмеден шығарылды. Басқа чат пайдаланушылардан белгілі бір пернелерді басуды сұрау, кез келген URL-ді көрсету немесе қай жерде екеніңізді көрсету - бұл уақытша қуғын-сүргінмен жазаланатын құқық бұзушылықтар. MSN автоматтандырылған жүйесінің ыңғайлылығы оның пайдаланушыларына проблемалар тудырды, бұл проблемаларды оң және теріс мазмұнды түсіндіруге қабілетті адам шеше алады. MSN Chat-тың жабылуының басты себебі - педофильдер мен басқа да жыныстық қылмыскерлерге чат-бөлмелер арқылы жастарға қол жеткізуге мүмкіндік беру. MSNBC бағдарламасында "Жетішіні ұстап алу" деп аталатын, ол балалар жыртқыштарды ұстауға арналған, балалар онлайн "достар"мен кездеседі, олар өздерінің жеке басы туралы шындықты айтады деп ойлады, бірақ шоуда педофилдер екені анықталды.
There were many documented problems from users about the MSN chat function. Most were directed to the “chat host.” This was a person who would enter the chat room under the name “host”, and act accordingly regulating the room. This service was useful for controlling the room, making sure that everyone was behaving accordingly, answering users’ questions about the rooms, and other assorted tasks. While the idea of a supervisor would put a lot of users at ease, there were reported disagreements between the two with what was considered appropriate. A claim was that there were a multitude of rules which the host didn’t make clear to the users, so many people were booted out of the room for breaking a rule they weren’t aware of. Any content that was viewed as offensive or sexually explicit was immediately removed and the person who wrote it was expelled from the room. Asking other chatters to press certain keys, displaying any kind of URL, or displaying what location you were from were all offenses punishable by temporary banishment. The convenience of an automated system for MSN led to problems for its users, problems solvable by a person able to interpret positive and negative content. A significant reason for MSN Chat shutting down was that it provided another opportunity for pedophiles and other sex offenders to have access to youth through the chat rooms. The MSNBC program, "To Catch a Predator", a show about catching child predators, showed children meeting up with online "friends" which they assumed were being truthful about their identity but, on the show, were revealed to be pedophiles.
Жабылу
2001 жылы Microsoft IRC клиенттері арқылы (соның ішінде Comic Chat) қатынасты тоқтатты, пайдаланушылардан тек браузер клиенттерін пайдалануды сұрады. 2003 жылы Microsoft компаниясы "жауапкершілікті жақсарту" үшін абоненттік модельге ауысуды жоспарлап, спаммен және балаларды жыныстық қорлау материалдарымен байланысты проблемаларға байланысты "Азияның көпшілігі" қоса алғанда, 28 елде "регуляцияланбаған" MSN Чат-бөлмелерін жабатынын мәлімдеді. Мессенджерлік чат-қызметтері ашық болды. MSN Chat жыл сайын 20 долларға жазылу қызметіне айналды. 2006 жылдың 31 тамызында Microsoft компаниясы MSN Chat енді ұсынылмайтынын жариялады. 2006 жылдың 16 қазанында MSN Chat серверлерін шамамен сағат 11: 30-да EST-те тоқтатты. Қызмет тоқтатылды, өйткені MSN енді абоненттік қызмет ретінде жұмыс істеу тиімді деп санамады.
In 2001, Microsoft closed access via IRC clients (including Comic Chat), asking users to exclusively use their browser client instead. In 2003, Microsoft announced that it would close "unregulated" MSN Chat rooms in 28 countries, including "most of Asia" due to problems with spam and concerns about child sexual abuse material, with plans to convert to a subscription model for "better accountability." Messenger chat services remained open. MSN Chat became a subscription service for $20/year. On August 31, 2006 Microsoft announced that MSN Chat would no longer be provided. On October 16, 2006 MSN Chat shut down their servers at about 11:30 a. m. EST. The service closed as allegedly MSN no longer deemed it profitable to run as a subscription service.