This is the new home of the egghelp.org community forum.
All data has been migrated (including user logins/passwords) to a new phpBB version.
For more information, see this announcement post . Click the X in the top right-corner of this box to dismiss this message.
Old posts that have not been replied to for several years.
egghead
Master
Posts: 481 Joined: Mon Oct 29, 2001 8:00 pm
Contact:
Post
by egghead » Tue Feb 10, 2004 11:10 am
Yeah, from that message:
Issue date: 07/02/2004
[snip]
Vendor status:
===============
Notified on 07 February 2004
/me nods
GodOfSuicide
Master
Posts: 463 Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria
Post
by GodOfSuicide » Thu Feb 12, 2004 7:17 am
btw, is there a patch for .13 out ? dont want to upgrade
ppslim
Revered One
Posts: 3914 Joined: Sun Sep 23, 2001 8:00 pm
Location: Liverpool, England
Post
by ppslim » Thu Feb 12, 2004 7:36 am
It has been fixed, though there are no work arounds other than to upgrade to 1.6.16 (when made available soon we hope) or to patch your current version.
Let me know what versions you want guys, and I will try and fix some patches up.
bobjuh
Master
Posts: 268 Joined: Wed Oct 03, 2001 8:00 pm
Location: Netherlands
Contact:
Post
by bobjuh » Thu Feb 12, 2004 10:32 am
Hope there will me a 1.6.13 patch soon.
I don't want to upgrade when 1.6.16 gets out and wait to see if there are bugs in it like in 1.6.15
GodOfSuicide
Master
Posts: 463 Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria
Post
by GodOfSuicide » Thu Feb 12, 2004 12:18 pm
from dun_dacil:
/* If it's a share bot that hasnt been sharing, ask again */
} else if (!(dcc.status & STAT_SHARE)) {
if (dcc.user && (bot_flags(dcc.user) & BOT_AGGRESSIVE)) {
dprintf(i, "s u?\n");
dcc.status |= STAT_OFFERED;
}
}
}
}
you just have to add a { behind the 2nd "...& BOT_AGGRESSIVE))" and a } behind "..STAT_OFFERED;"
ppslim
Revered One
Posts: 3914 Joined: Sun Sep 23, 2001 8:00 pm
Location: Liverpool, England
Post
by ppslim » Fri Feb 13, 2004 3:42 pm
I would advise an upgrade to 1.6.16 when it comes out.
There are a few bugs that have been ironed out in the source tree. IPv6 has been stripped, which was the mega headache.
MasterJM
Halfop
Posts: 56 Joined: Wed Apr 03, 2002 8:00 pm
Location: germany
Contact:
Post
by MasterJM » Sun Feb 15, 2004 2:59 pm
ppslim wrote: I would advise an upgrade to 1.6.16 when it comes out.
There are a few bugs that have been ironed out in the source tree. IPv6 has been stripped, which was the mega headache.
wooo
when is .16 going public for release?
I hope soon
because this
http://www.securityfocus.com/bid/9606/info/ is not good :<
MfG JM
-good old time
]Kami[
Owner
Posts: 590 Joined: Thu Jul 24, 2003 2:59 pm
Location: Slovenia
Contact:
Post
by ]Kami[ » Sun Feb 15, 2004 8:20 pm
Yeah saw about bug, strange that nobody discovered it so long...
I
Ice--Cube
Post
by Ice--Cube » Thu Apr 01, 2004 5:45 pm
I really hope that eggdrop and windrop 1.6.16 will be reelased soon, becource this exploit is a serius problem...i have experienced some attacks on my botnet myself...
I
Ice--Cube
Post
by Ice--Cube » Wed Apr 07, 2004 8:12 am
Does anybody know how to patch windrop 1.6.15 from this vulnerability?
dollar
Op
Posts: 178 Joined: Tue Oct 28, 2003 3:47 pm
Location: Netherlands
Post
by dollar » Wed Apr 07, 2004 9:38 am
Ice--Cube wrote: Does anybody know how to patch windrop 1.6.15 from this vulnerability?
Just make sure every bot has a pass, and you'll be fine.
dollar (or something similar) at:
#eggdrop / #tcl - undernet
#egghelp / #tcl / #eggtcl - efnet
#eggdrop.support / #tcl - quakenet
#eggdrop - ircnet
I
Ice--Cube
Post
by Ice--Cube » Wed Apr 14, 2004 5:32 pm
They have passes..but attacker can still hack in one egg and op itself on channels...