<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/4986" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2003-07-17T05:24:24-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/4986</id>

		<entry>
		<author><name><![CDATA[ppslim]]></name></author>
		<updated>2003-07-17T05:24:24-04:00</updated>

		<published>2003-07-17T05:24:24-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23596#p23596</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23596#p23596"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23596#p23596"><![CDATA[
I have had a look at the problem reported, and so far am unable to replicate what has been shown.<br><br>So far, I have only generated 15 nickname likes those discribed in the report, so guess I might need to try further (500+ say).<br><br>There are however a few things to consider in what tests they conducted.<br><br>1: They removed scripts, due didn't restart the bot fully<br>2: Learn users (as sugested)<br><br>You should note to them, if they feel there are bugs, to present further and more clear evidance of what happened. It would help a lot if we knew exactly what nicknames and idents caused it to happen on there systems.<br><br>As for password sniffing. This is somthing that would also need to be elaborated further. I can name a few ways to sniff out password in eggdrop, but these are known, and are more a side effect of the debug process.<br><br>Scripts again can cause this. I have a bug in my own secure logging system that shows peoples passwords (it's still perfectly secure thank god).<br><br>While I am not going to deny outright that these issues do not exist, as there may be perfectly good explanations, they may be bugs they may be somthing else. The fact remains, what they presented was small and has obviously never been seen by the development team, there was also a lack of information (though there may be good grounds for that).<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2">ppslim</a> — Thu Jul 17, 2003 5:24 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2003-07-16T10:30:14-04:00</updated>

		<published>2003-07-16T10:30:14-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23558#p23558</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23558#p23558"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23558#p23558"><![CDATA[
The only thing that comes in my mind about the +n thing is that some (l)users forgot to remove the learn users and/or the open telnets, I mean set them to 0 after they made theyr *first* account, when they are creating the userfile for the first time. Hope this is the *real* problem.. <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Wed Jul 16, 2003 10:30 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Dedan]]></name></author>
		<updated>2003-07-16T09:26:11-04:00</updated>

		<published>2003-07-16T09:26:11-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23554#p23554</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23554#p23554"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23554#p23554"><![CDATA[
Does there seem to be a real abuse?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3472">Dedan</a> — Wed Jul 16, 2003 9:26 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[FIDe`]]></name></author>
		<updated>2003-07-16T06:22:18-04:00</updated>

		<published>2003-07-16T06:22:18-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23548#p23548</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23548#p23548"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23548#p23548"><![CDATA[
<span style="text-decoration:underline">egghead</span>, I forwarded to guppy the infos that the admin gave me about that issues  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2739">FIDe`</a> — Wed Jul 16, 2003 6:22 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[GodOfSuicide]]></name></author>
		<updated>2003-07-16T02:28:31-04:00</updated>

		<published>2003-07-16T02:28:31-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23542#p23542</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23542#p23542"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23542#p23542"><![CDATA[
i havent found anything about this yet..(packetstorm etc)<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=1433">GodOfSuicide</a> — Wed Jul 16, 2003 2:28 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Dedan]]></name></author>
		<updated>2003-07-15T17:13:40-04:00</updated>

		<published>2003-07-15T17:13:40-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23533#p23533</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23533#p23533"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23533#p23533"><![CDATA[
I would like to know if there is abuse.<br>I am not asking for information about<br>it, just if there is one.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3472">Dedan</a> — Tue Jul 15, 2003 5:13 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[FIDe`]]></name></author>
		<updated>2003-07-15T14:47:01-04:00</updated>

		<published>2003-07-15T14:47:01-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23525#p23525</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23525#p23525"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23525#p23525"><![CDATA[
ok, I'm going to send a mail to the admin, if he tells me something interesting I will forward it to guppy   <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_wink.gif" width="15" height="15" alt=":wink:" title="Wink"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2739">FIDe`</a> — Tue Jul 15, 2003 2:47 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[egghead]]></name></author>
		<updated>2003-07-15T11:34:57-04:00</updated>

		<published>2003-07-15T11:34:57-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23510#p23510</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23510#p23510"/>
		<title type="html"><![CDATA[Re: fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23510#p23510"><![CDATA[
<blockquote class="uncited"><div>today, logging in my outlandz.net shell account, I found this in MOTD:<br><br>                           |<br>|**NOTICE**<br>                           |<br>| "Eggdrop.1.6.15 is a bug trap. it creates new +n users. do NOT upgrade to it."<br> Its openly exploitable.   |<br>|<br>                           |<br>|7/14/03<br><br>anyone knows about it..?<br>I hope it's a hoax.<br>tnx for answers</div></blockquote>FIDe`, can you contact the admins of that shell and ask them to forward any info on that exploit, if there is one, and forward it to guppy privately?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=282">egghead</a> — Tue Jul 15, 2003 11:34 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[guppy]]></name></author>
		<updated>2003-07-15T11:32:33-04:00</updated>

		<published>2003-07-15T11:32:33-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23509#p23509</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23509#p23509"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23509#p23509"><![CDATA[
not that I know of -- 1.6.15 has bugs but none of them are security ones as far as I know.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10">guppy</a> — Tue Jul 15, 2003 11:32 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[FIDe`]]></name></author>
		<updated>2003-07-15T09:42:19-04:00</updated>

		<published>2003-07-15T09:42:19-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=23503#p23503</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=23503#p23503"/>
		<title type="html"><![CDATA[fanthomatic eggdrop 1.6.15 exploit?]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=23503#p23503"><![CDATA[
today, logging in my outlandz.net shell account, I found this in MOTD:<br><br>                           |<br>|**NOTICE**<br>                           |<br>| "Eggdrop.1.6.15 is a bug trap. it creates new +n users. do NOT upgrade to it."<br> Its openly exploitable.   |<br>|<br>                           |<br>|7/14/03<br><br>anyone knows about it..?<br>I hope it's a hoax.<br>tnx for answers<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2739">FIDe`</a> — Tue Jul 15, 2003 9:42 am</p><hr />
]]></content>
	</entry>
	</feed>
