This is the new home of the egghelp.org community forum.
All data has been migrated (including user logins/passwords) to a new phpBB version.


For more information, see this announcement post. Click the X in the top right-corner of this box to dismiss this message.

supposed 1.6.x eggdrop exploit posted on bugtraq

Old posts that have not been replied to for several years.
s
subsoniq

supposed 1.6.x eggdrop exploit posted on bugtraq

Post by subsoniq »

I'm not a programmer so I cant' make heads or tails if this is legitimate:

http://www.securityfocus.com/archive/1/ ... 04-02-13/0
b
bobjuh
Master
Posts: 268
Joined: Wed Oct 03, 2001 8:00 pm
Location: Netherlands
Contact:

Re: supposed 1.6.x eggdrop exploit posted on bugtraq

Post by bobjuh »

subsoniq wrote:I'm not a programmer so I cant' make heads or tails if this is legitimate:

http://www.securityfocus.com/archive/1/ ... 04-02-13/0
The origenal mail

http://mogan.nonsoloirc.com/egg_advisory.txt also was send to eggdev list
e
egghead
Master
Posts: 481
Joined: Mon Oct 29, 2001 8:00 pm
Contact:

Re: supposed 1.6.x eggdrop exploit posted on bugtraq

Post by egghead »

bobjuh wrote: The origenal mail

http://mogan.nonsoloirc.com/egg_advisory.txt also was send to eggdev list
Yeah, from that message:
Issue date: 07/02/2004
[snip]
Vendor status:
===============
Notified on 07 February 2004
/me nods
User avatar
GodOfSuicide
Master
Posts: 463
Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria

Post by GodOfSuicide »

btw, is there a patch for .13 out ? dont want to upgrade
p
ppslim
Revered One
Posts: 3914
Joined: Sun Sep 23, 2001 8:00 pm
Location: Liverpool, England

Post by ppslim »

It has been fixed, though there are no work arounds other than to upgrade to 1.6.16 (when made available soon we hope) or to patch your current version.

Let me know what versions you want guys, and I will try and fix some patches up.
b
bobjuh
Master
Posts: 268
Joined: Wed Oct 03, 2001 8:00 pm
Location: Netherlands
Contact:

Post by bobjuh »

Hope there will me a 1.6.13 patch soon.
I don't want to upgrade when 1.6.16 gets out and wait to see if there are bugs in it like in 1.6.15
User avatar
GodOfSuicide
Master
Posts: 463
Joined: Mon Jun 17, 2002 8:00 pm
Location: Austria

Post by GodOfSuicide »

from dun_dacil:
/* If it's a share bot that hasnt been sharing, ask again */
} else if (!(dcc.status & STAT_SHARE)) {
if (dcc.user && (bot_flags(dcc.user) & BOT_AGGRESSIVE)) {
dprintf(i, "s u?\n");
dcc.status |= STAT_OFFERED;
}
}
}
}


you just have to add a { behind the 2nd "...& BOT_AGGRESSIVE))" and a } behind "..STAT_OFFERED;"
p
ppslim
Revered One
Posts: 3914
Joined: Sun Sep 23, 2001 8:00 pm
Location: Liverpool, England

Post by ppslim »

I would advise an upgrade to 1.6.16 when it comes out.

There are a few bugs that have been ironed out in the source tree. IPv6 has been stripped, which was the mega headache.
M
MasterJM
Halfop
Posts: 56
Joined: Wed Apr 03, 2002 8:00 pm
Location: germany
Contact:

Post by MasterJM »

ppslim wrote:I would advise an upgrade to 1.6.16 when it comes out.

There are a few bugs that have been ironed out in the source tree. IPv6 has been stripped, which was the mega headache.
wooo

when is .16 going public for release?
I hope soon :)

because this http://www.securityfocus.com/bid/9606/info/ is not good :<

MfG JM
-good old time
User avatar
]Kami[
Owner
Posts: 590
Joined: Thu Jul 24, 2003 2:59 pm
Location: Slovenia
Contact:

Post by ]Kami[ »

Yeah saw about bug, strange that nobody discovered it so long...
r
reaction

eggdrop 1.6.13 patch

Post by reaction »

if those two {} fix the vulnerability, here is the patch for 1.6.13

http://www.lownoise.org/downloads/eggdr ... tion.patch

patch -p0 < eggdrop1.6.13+p1_ReAction.patch from outside eggdrop1.6.13 directory.

have fun

ReAction
I
Ice--Cube

Post by Ice--Cube »

I really hope that eggdrop and windrop 1.6.16 will be reelased soon, becource this exploit is a serius problem...i have experienced some attacks on my botnet myself... :roll:
I
Ice--Cube

Post by Ice--Cube »

Does anybody know how to patch windrop 1.6.15 from this vulnerability?
d
dollar
Op
Posts: 178
Joined: Tue Oct 28, 2003 3:47 pm
Location: Netherlands

Post by dollar »

Ice--Cube wrote:Does anybody know how to patch windrop 1.6.15 from this vulnerability?
Just make sure every bot has a pass, and you'll be fine.
dollar (or something similar) at:
#eggdrop / #tcl - undernet
#egghelp / #tcl / #eggtcl - efnet
#eggdrop.support / #tcl - quakenet
#eggdrop - ircnet
I
Ice--Cube

Post by Ice--Cube »

They have passes..but attacker can still hack in one egg and op itself on channels...
Locked