This is the new home of the egghelp.org community forum.
All data has been migrated (including user logins/passwords) to a new phpBB version.


For more information, see this announcement post. Click the X in the top right-corner of this box to dismiss this message.

share.mod bug could be used for an exploit

Old posts that have not been replied to for several years.
Locked
User avatar
GodOfSuicide
Master
Posts: 463
Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria

share.mod bug could be used for an exploit

Post by GodOfSuicide »

A tricky attacker can gain the control over (almost) any eggdrop botnet. the bug rely in the fact that every legitimate bot can gain share status even if it is not marked to share with someone
check http://www.securityfocus.com/archive/1/ ... 04-02-13/0 and apply the included patch
User avatar
Dedan
Master
Posts: 260
Joined: Wed Jul 09, 2003 10:50 pm
Location: Memphis

Post by Dedan »

are stand alone bots imune?
I once was an intelligent young man, now i am old and i can not remember who i was.
b
bobjuh
Master
Posts: 268
Joined: Wed Oct 03, 2001 8:00 pm
Location: Netherlands
Contact:

Post by bobjuh »

http://forum.egghelp.org/viewtopic.php?t=6813

There is already a topic open about die share.mod bug
User avatar
GodOfSuicide
Master
Posts: 463
Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria

Post by GodOfSuicide »

bobjuh wrote:http://forum.egghelp.org/viewtopic.php?t=6813

There is already a topic open about die share.mod bug
in fact, this one was open befor the other one :D
s
spock
Master
Posts: 319
Joined: Thu Dec 12, 2002 8:40 pm

Post by spock »

lies
photon?
b
bobjuh
Master
Posts: 268
Joined: Wed Oct 03, 2001 8:00 pm
Location: Netherlands
Contact:

Post by bobjuh »

No The other one was earlyer

This post

Posted: Tue Feb 10, 2004 12:02 pm Post subject: share.mod bug could be used for an exploit

and the other

Posted: Tue Feb 10, 2004 4:41 am Post subject: supposed 1.6.x eggdrop exploit posted on bugtraq
Locked