<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/589" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2001-12-13T09:23:00-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/589</id>

		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2001-12-13T09:23:00-04:00</updated>

		<published>2001-12-13T09:23:00-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=2711#p2711</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=2711#p2711"/>
		<title type="html"><![CDATA[security BUG report for LolToolz6.2]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=2711#p2711"><![CDATA[
Thank you ppslim, this function is working fine now :] <br><br>// Don't Be Lazy, redownload this script now, don't forget to change pub prefix and other settings, cos everything is changed to default : ] //<br><br>Goodluck<br><p>Statistics: Posted by Guest — Thu Dec 13, 2001 9:23 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2001-12-13T09:08:00-04:00</updated>

		<published>2001-12-13T09:08:00-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=2709#p2709</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=2709#p2709"/>
		<title type="html"><![CDATA[security BUG report for LolToolz6.2]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=2709#p2709"><![CDATA[
little corecttion :<br><a href="http://www.ppslim.ukshells.co.uk/netbots/lol.tcl" class="postlink">http://www.ppslim.ukshells.co.uk/netbots/lol.tcl</a><br><br>GL<br><p>Statistics: Posted by Guest — Thu Dec 13, 2001 9:08 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[ppslim]]></name></author>
		<updated>2001-12-12T23:53:00-04:00</updated>

		<published>2001-12-12T23:53:00-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=2695#p2695</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=2695#p2695"/>
		<title type="html"><![CDATA[security BUG report for LolToolz6.2]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=2695#p2695"><![CDATA[
I have posted a bug fixed version to <a href="http://www.ppslim.ukshells.co.uk/netbots/lo.tcl" class="postlink">http://www.ppslim.ukshells.co.uk/netbots/lo.tcl</a><br><br>It looks like this script is no longer in production, so I will package it up, and send it on to slennox for inclusion in the archive.<br><br>If there are any others, that find security bugs in scripts from the archive, please report them (it's like you to give me all you money, but what the hell) here. I will try my best (as will the tohers), to make bug fixes, and get them included in the Tcl archive.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2">ppslim</a> — Wed Dec 12, 2001 11:53 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2001-12-12T14:36:00-04:00</updated>

		<published>2001-12-12T14:36:00-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=2670#p2670</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=2670#p2670"/>
		<title type="html"><![CDATA[security BUG report for LolToolz6.2]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=2670#p2670"><![CDATA[
the bug was found in chattr function, it allow users who has a flag +o ( global or on channel, it doesn't matter ), to become a bot master or a owner very easilly. I strongly recommend you to change these rows :<br><br>bind pub o|o [string trim $lol(cmdchar)]chattr pub_lol_chattr<br><br>bind msg o|o chattr msg_lol_chattr<br><br>to :<br><br>bind pub n|n [string trim $lol(cmdchar)]chattr pub_lol_chattr<br><br>bind msg n|n chattr msg_lol_chattr<br><br>so this function now can use only user who has the +n flag. If someone wants to rewrite this function i can say how this bug is working.<br><br>I think this is the first post about this bug here.. Thank for your attention <br><br>Keep looking ...<br><p>Statistics: Posted by Guest — Wed Dec 12, 2001 2:36 pm</p><hr />
]]></content>
	</entry>
	</feed>
