As #ICQ is shut down in a few days I think I can disclose this now:
Long long time ago, the official ICQ client allowed #flash avatars. It was possible to use custom flash avatars (from a webserver controlled by me) by uploading a special XML file pointing to that URL using the Miranda (?) ICQ plugin.
The flash avatars allowed #ActionScript and the flash player was running as local user. The intended use case was animated avatars (I send a smiley and the avatar smiles).
I crafted a flash file that displayed a static picture (so nobody will notice its a flash avatar), but opened a http connection to my server and waited for commands. I just used this to run "play this mp3 from that URL" and prank people and never used it for something evil. Never tried to figure out what was possible in terms of local access etc. and never disclosed this possibility until now.
#icq #hacking #infosec