<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/17380" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2009-12-23T23:44:00-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/17380</id>

		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2009-12-23T23:44:00-04:00</updated>

		<published>2009-12-23T23:44:00-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91425#p91425</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91425#p91425"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91425#p91425"><![CDATA[
As I wrote, the needed procs to "decrypt" this bad-boy is available in user's post. Once you got the dezip proc loaded, all you need to do is issue the dezip tcl command with the various strings that you'd like to decrypt..<br><br>I sure do hope that you don't actually intend to run this horrible piece of trojan/backdoor. Having your eggdrop joining some strange channels are the least of your concern, as it attempts to create a new owner's record, as well as replacing any command to list users in order to hide this... In the end, this bad-boy is written to allow it's author (or other malicious users) full access to your eggdrop, and the shell that is hosting it.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Wed Dec 23, 2009 11:44 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[dec]]></name></author>
		<updated>2009-12-23T15:58:32-04:00</updated>

		<published>2009-12-23T15:58:32-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91422#p91422</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91422#p91422"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91422#p91422"><![CDATA[
hai <strong class="text-strong">nml375</strong> and <strong class="text-strong">blake</strong>,<br>i have try <strong class="text-strong">User</strong> tcl script to convert the <strong class="text-strong">"backdoor-script"</strong><br>but still got nothing when i use the convert-result..<br>my bot still running to some strange channel..<br><br>the point is, still dont understand what the meaning of <br>this <strong class="text-strong">headache</strong> word..  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_cry.gif" width="15" height="15" alt=":cry:" title="Crying or Very sad"> <br><div class="codebox"><p>Code: </p><pre><code>1. if {[string tolower $channel] != [dezip "EQO/7.meDlC1iq2jE.UVfbE."]} {2. set notc [dezip "c4c0O/Pz7NR0VY05E/t9zZo.PzSIW0c035C/"]3. regsub -all -- [dezip "jGBDx04~ntxb0"] $text "" text4. regsub -all -- [dezip "bFuC0.Jq~aEc0"] $text "" text5. regsub -all -- [dezip "xdxsF1~hBM6q0"] $text "" text6. regsub -all -- [dezip "jG~BDx04ntxb0"] $text "" text7. regsub -all -- [dezip "bF~uC0.JqaEc0"] $sreas "" sreas8. regsub -all -- [dezip "xdxs~F1hBM6q0"] $sreas "" sreas </code></pre></div>*still need help..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10991">dec</a> — Wed Dec 23, 2009 3:58 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2009-12-22T11:39:57-04:00</updated>

		<published>2009-12-22T11:39:57-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91418#p91418</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91418#p91418"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91418#p91418"><![CDATA[
The thread that Blake linked contains all the needed information to de-obfuscate the lines you posted, including the dezip proc.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Tue Dec 22, 2009 11:39 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[dec]]></name></author>
		<updated>2009-12-22T11:12:45-04:00</updated>

		<published>2009-12-22T11:12:45-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91417#p91417</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91417#p91417"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91417#p91417"><![CDATA[
still blank.. <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_sad.gif" width="15" height="15" alt=":(" title="Sad"><br>any other way to know how to decrypt the <strong class="text-strong">dezip</strong> code..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10991">dec</a> — Tue Dec 22, 2009 11:12 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[blake]]></name></author>
		<updated>2009-12-10T10:41:51-04:00</updated>

		<published>2009-12-10T10:41:51-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91258#p91258</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91258#p91258"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91258#p91258"><![CDATA[
<a href="http://forum.egghelp.org/viewtopic.php?t=6708&amp;highlight=netgate+backdoor" class="postlink">http://forum.egghelp.org/viewtopic.php? ... e+backdoor</a><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10512">blake</a> — Thu Dec 10, 2009 10:41 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[dec]]></name></author>
		<updated>2009-12-10T10:28:29-04:00</updated>

		<published>2009-12-10T10:28:29-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91256#p91256</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91256#p91256"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91256#p91256"><![CDATA[
haii nml375<br>1st thing 1st verry sorry for the crosspost.<br><br>2nd thing is, can you redirect me to the post that you mention before..<br>i've try to search but i found lot of post by "user"<br>verry appreciate for your help before..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10991">dec</a> — Thu Dec 10, 2009 10:28 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2009-11-26T18:47:07-04:00</updated>

		<published>2009-11-26T18:47:07-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91081#p91081</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91081#p91081"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91081#p91081"><![CDATA[
<span style="color:red">Please don't crosspost. I will remove your other post in "Script Requests".</span><br><br>Are you thinking of the old netgate backdoor/trojan? Then you'll find a post by "user" on how you could decrypt that code on the forum...<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Thu Nov 26, 2009 6:47 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[dec]]></name></author>
		<updated>2009-11-26T17:53:14-04:00</updated>

		<published>2009-11-26T17:53:14-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=91079#p91079</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=91079#p91079"/>
		<title type="html"><![CDATA[translate encrypted word]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=91079#p91079"><![CDATA[
i found some script that have backdoor..<br>1 need help for decrypted on at least translate with word that i can understand.. <div class="codebox"><p>Code: </p><pre><code>1. if {[string tolower $channel] != [dezip "EQO/7.meDlC1iq2jE.UVfbE."]} {2. set notc [dezip "c4c0O/Pz7NR0VY05E/t9zZo.PzSIW0c035C/"]3. regsub -all -- [dezip "jGBDx04~ntxb0"] $text "" text4. regsub -all -- [dezip "bFuC0.Jq~aEc0"] $text "" text5. regsub -all -- [dezip "xdxsF1~hBM6q0"] $text "" text6. regsub -all -- [dezip "jG~BDx04ntxb0"] $text "" text7. regsub -all -- [dezip "bF~uC0.JqaEc0"] $sreas "" sreas8. regsub -all -- [dezip "xdxs~F1hBM6q0"] $sreas "" sreas</code></pre></div>thank you so much for help in advance..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10991">dec</a> — Thu Nov 26, 2009 5:53 pm</p><hr />
]]></content>
	</entry>
	</feed>
