<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/14004" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2007-10-15T16:53:16-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/14004</id>

		<entry>
		<author><name><![CDATA[LordSephiroth]]></name></author>
		<updated>2007-10-15T16:53:16-04:00</updated>

		<published>2007-10-15T16:53:16-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76773#p76773</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76773#p76773"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76773#p76773"><![CDATA[
<blockquote class="uncited"><div>Has anyone checked if 1.7.0 is affected also?</div></blockquote>It appears to be.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9322">LordSephiroth</a> — Mon Oct 15, 2007 4:53 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DragnLord]]></name></author>
		<updated>2007-10-13T12:29:56-04:00</updated>

		<published>2007-10-13T12:29:56-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76704#p76704</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76704#p76704"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76704#p76704"><![CDATA[
Has anyone checked if 1.7.0 is affected also?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=4461">DragnLord</a> — Sat Oct 13, 2007 12:29 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[LordSephiroth]]></name></author>
		<updated>2007-10-11T15:38:40-04:00</updated>

		<published>2007-10-11T15:38:40-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76633#p76633</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76633#p76633"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76633#p76633"><![CDATA[
His patch also addresses 3 other similar issues<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9322">LordSephiroth</a> — Thu Oct 11, 2007 3:38 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[slennox]]></name></author>
		<updated>2007-10-11T05:13:52-04:00</updated>

		<published>2007-10-11T05:13:52-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76599#p76599</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76599#p76599"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76599#p76599"><![CDATA[
Got my first concerned e-mail about this issue with the exploit having appeared on Packet Storm. It's probably time to post the patch on the main egghelp.org site in the absence of any movement on eggdev. Has anyone other than TCL_no_TK tried the patch and also found it works fine?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=13034">slennox</a> — Thu Oct 11, 2007 5:13 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[LordSephiroth]]></name></author>
		<updated>2007-09-20T13:52:53-04:00</updated>

		<published>2007-09-20T13:52:53-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76073#p76073</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76073#p76073"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76073#p76073"><![CDATA[
Since I was the one that found this, I'll comment on it and explain it. My intentions of reporting it weren't exactly what came of it, which I will explain it a moment.<br><br>First, the vulnerability MUST be exploited from a malicious server. The advisories listed are somewhat-correct, but mostly incorrect. The message itself doesn't have to be overly long, but the nick/user/hostname does. It uses an unchecked strcpy() to copy the data into a small stack variable, obviously resulting in a stack overflow. So, like I said in the Bugzilla posting, you could open a netcat listener, connect the bot to it and send this string:<br><br>:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br>AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br>AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br>AAAAAAAAAAAAAAAAAAAABBBB PRIVMSG Lamestbot :test<br><br>That (should) overwrite the instruction pointer with 0x42424242 (BBBB), which would allow an attacker to execute arbitrary code. The large number of A's is where the nick!user@host would normally be.<br><br>My intention with reporting this was for the devs to see the many variants of this vulnerability in the eggdrop code. I didn't bother recording or reporting them all, but I spent about 30 minutes flipping through the code and ran across several others that could be exploited in a similar fashion. I've been meaning to go back through them all and release a patch, but I just haven't had time.<br><br>As for the seriousness, it isn't that critical because it does require some social engineering to exploit. You would have to connect your bot (or someone from the partyline would) to a malicious 'server' that would then exploit the vulnerability. Granted, there are other attacks that could be used to facilitate this attack, but they all require the bot to connect to a malicious listener at some point. I use the word server lightly, because all it has to be is a malicious listener and doesn't need to be an IRCd.<br><br>I hope that helps. I've been meaning to go through and do a full audit of the eggy code, but like I said, I just haven't had the time and it didn't seem to me like there would be much interest in doing so.<br><br>EDIT: changed some things around (1:56 PM EST, Sept. 20th 2007)<br>EDIT #2:<br><br>Sorry, I edit a lot :p Last one, I hope...<br><br>I have followed this bug somewhat since I released it a few months ago, IIRC NetBSD was the first to release a patch, I saw the Gentoo patch a few days ago, but I haven't seen an 'official' patch from the eggie devs.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9322">LordSephiroth</a> — Thu Sep 20, 2007 1:52 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2007-09-19T16:44:06-04:00</updated>

		<published>2007-09-19T16:44:06-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76041#p76041</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76041#p76041"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76041#p76041"><![CDATA[
1:<br>To my best knowledge, only malicious servers would permit the sending of such large messages, but with the huge flora of modified ircd-software out there these days, I cannot give a 100% guarantee that non-malicious servers cannot be used to relay messages exploiting this bug.<br><br>2:<br>1.6.18 + the patch included in the bugzilla link posted earlier<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Wed Sep 19, 2007 4:44 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[sKy]]></name></author>
		<updated>2007-09-19T16:40:16-04:00</updated>

		<published>2007-09-19T16:40:16-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=76039#p76039</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=76039#p76039"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=76039#p76039"><![CDATA[
Question 1:<br>Only an malicious server could use that bug to execute code on remote?<br><br>Question 2:<br>Is there a version without that bug yet? Or can you advice some bundle like eggdrop version x + patch?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=6101">sKy</a> — Wed Sep 19, 2007 4:40 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[awyeah]]></name></author>
		<updated>2007-09-17T12:30:30-04:00</updated>

		<published>2007-09-17T12:30:30-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75983#p75983</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75983#p75983"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75983#p75983"><![CDATA[
I must also say the same for myself, studies, work, family, friends and other chores keep my agenda full daily almost on weekdays and on weekends. As apart for the devteam, I don't think am really that capable also.<br><br>But I do hope in the future there still will be progress on the eggdrop project and newer versions would come out, eventhough its like a still project since the devteam doesnt have enough people and they are also busy with their lives and don't have time for their aside hobbies; eggdrop development.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=4875">awyeah</a> — Mon Sep 17, 2007 12:30 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2007-09-17T12:19:38-04:00</updated>

		<published>2007-09-17T12:19:38-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75982#p75982</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75982#p75982"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75982#p75982"><![CDATA[
If I'd had the time for it, I would probably try to get involved again (even tho it's been several years since I was in any way involved). Unfortunately, I don't as studies and work take more than enough time as is..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Mon Sep 17, 2007 12:19 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[awyeah]]></name></author>
		<updated>2007-09-16T20:34:48-04:00</updated>

		<published>2007-09-16T20:34:48-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75978#p75978</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75978#p75978"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75978#p75978"><![CDATA[
<blockquote class="uncited"><div>However, as I've been made to understand, eggheads devteam really could use some new coders with time/inspiration to work with the code.<br>Many projects like eggdrop depend on new coders, as people tend to less time to spend as years pass.</div></blockquote>Well nml375 you stand out as a good candidate for the eggheads devteam, given the time.  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_razz.gif" width="15" height="15" alt=":P" title="Razz"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=4875">awyeah</a> — Sun Sep 16, 2007 8:34 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[TCL_no_TK]]></name></author>
		<updated>2007-09-16T18:00:29-04:00</updated>

		<published>2007-09-16T18:00:29-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75974#p75974</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75974#p75974"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75974#p75974"><![CDATA[
<blockquote class="uncited"><div>My opinion, is that it should be tended to as soon as possible. Serious or not, it should be sorted out to no blacken eggdrop's name any further.. </div></blockquote> Yes, well said <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> <blockquote class="uncited"><div>I've just been digging through the commitlogs of the cvs-repository, and have not seen any traces of this being patched sofar.. Only update in 2007 regarding 1.6 seems to be changing the Copyright date to 2007</div></blockquote> I've tryed the patch from the bugzilla url you posted, ty for that btw. I used it patch the latest cvs version of eggdrop1.6 <blockquote class="uncited"><div>~/eggdrop1.6 $ patch -p0 &lt; 01_CVE-2007-2807_servmsg.patch<br>patching file src/mod/server.mod/servmsg.c<br>~/eggdrop1.6 $</div></blockquote> so works great <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_cool.gif" width="15" height="15" alt="8)" title="Cool"> <blockquote class="uncited"><div>However, as I've been made to understand, eggheads devteam really could use some new coders with time/inspiration to work with the code.<br>Many projects like eggdrop depend on new coders, as people tend to less time to spend as years pass. </div></blockquote> I'm not good at this myself but i would love to help <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> I never really knew there was still a need for coders since there was so much dev going on with the eggdrop1.9 branch <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_confused.gif" width="15" height="15" alt=":?" title="Confused"> sorry :/ Thanks for your input nml375 <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy"> tis really apreshiated.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8130">TCL_no_TK</a> — Sun Sep 16, 2007 6:00 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2007-09-16T16:13:01-04:00</updated>

		<published>2007-09-16T16:13:01-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75972#p75972</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75972#p75972"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75972#p75972"><![CDATA[
My opinion, is that it should be tended to as soon as possible. Serious or not, it should be sorted out to no blacken eggdrop's name any further..<br><br>However, as I've been made to understand, eggheads devteam really could use some new coders with time/inspiration to work with the code.<br>Many projects like eggdrop depend on new coders, as people tend to less time to spend as years pass.<br><br>edit:<br><em class="text-italics">I've just been digging through the commitlogs of the cvs-repository, and have not seen any traces of this being patched sofar.. Only update in 2007 regarding 1.6 seems to be changing the Copyright date to 2007</em><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Sun Sep 16, 2007 4:13 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[TCL_no_TK]]></name></author>
		<updated>2007-09-16T15:45:52-04:00</updated>

		<published>2007-09-16T15:45:52-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75971#p75971</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75971#p75971"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75971#p75971"><![CDATA[
Thanks, I haven't checked if this is in the cvs version of eggdrop, as thats the only version i tend to be using these days. <blockquote class="uncited"><div>So there's nothing to be afraid of if you use the most recent version of Eggdrop (currently 1.6.18).</div></blockquote> Thanks <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> <blockquote class="uncited"><div>It is a known issue, and have been reported to eggheads since long.<br>I believe there are several different patches for it aswell. </div></blockquote> <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_sad.gif" width="15" height="15" alt=":(" title="Sad"> sorry, didn't check the bugzilla, thou i had thought that this bug might of been reported already so i thought i would like to know a bit more about the seriousness of the expliot. <blockquote class="uncited"><div>The impact of this bug might be argued, as it would require an attacker to manipulate an user to use a malicious server. Still it's fully exploitable under those conditions.</div></blockquote> Yes, i agree. And can see the point, thou i could still say that possibity is deffonatly still out there as there have been troubles with dns fowards to an differant server from some network address. <blockquote class="uncited"><div>I assume the patch is saved for a future release of 1.6.19, although I don't know if it has been added to the cvs-repository..</div></blockquote> Hope so <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> thought i've seen alot of projects these days that have problems with expliots in there code. Like anope irc services having alot of problems with there mysql, in my opinion that really caused them alot of bother. <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_sad.gif" width="15" height="15" alt=":(" title="Sad"> After thinking this through and the means which it takes to expliot eggdrop this way. I would assume that it would probably not happen unless you went to alot of trouble to make it happen. What do you guys think?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8130">TCL_no_TK</a> — Sun Sep 16, 2007 3:45 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2007-09-15T19:01:22-04:00</updated>

		<published>2007-09-15T19:01:22-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75963#p75963</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75963#p75963"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75963#p75963"><![CDATA[
That would be gentoo's patched package... the eggdrop you would download from eggheads is indeed flawed with this bug.<br><br>The impact of this bug might be argued, as it would require an attacker to manipulate an user to use a malicious server. Still it's fully exploitable under those conditions. I assume the patch is saved for a future release of 1.6.19, although I don't know if it has been added to the cvs-repository..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Sat Sep 15, 2007 7:01 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Sir_Fz]]></name></author>
		<updated>2007-09-15T16:40:08-04:00</updated>

		<published>2007-09-15T16:40:08-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=75961#p75961</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=75961#p75961"/>
		<title type="html"><![CDATA[Possible expliot in eggdrop's server module?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=75961#p75961"><![CDATA[
<blockquote class="uncited"><div>Affected Packages<br><br>Package: net-irc/eggdrop<br>Vulnerable: &lt; 1.6.18-r2<br>Unaffected: &gt;= 1.6.18-r2<br>Architectures: All supported architectures</div></blockquote>So there's nothing to be afraid of if you use the most recent version of Eggdrop (currently 1.6.18).<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3085">Sir_Fz</a> — Sat Sep 15, 2007 4:40 pm</p><hr />
]]></content>
	</entry>
	</feed>
