<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>IRC-Junkie.org - IRC News &#187; Hack</title>
	<atom:link href="http://www.irc-junkie.org/category/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.irc-junkie.org</link>
	<description>All about Internet Relay Chat</description>
	<lastBuildDate>Sun, 27 Nov 2011 23:50:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.irc-junkie.org/?pushpress=hub'/>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/de/</creativeCommons:license>		<item>
		<title>IRC Defender arbitrary code execution exploit</title>
		<link>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/</link>
		<comments>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/#comments</comments>
		<pubDate>Sun, 27 Nov 2011 22:18:15 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Network Addons]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[IRC-Defender]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1274</guid>
		<description><![CDATA[Yesterday, news broke that there is an arbitrary code execution exploit within the still popular IRC security service IRC Defender which is, according to the reporter, being actively exploited.

The flaw is said to be within the InspIRCd link module for which a patched version exists, but according to the original post to the IRC-Security ...<p><a href="http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/">IRC Defender arbitrary code execution exploit</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-06-07/irc-defender-15-released/' rel='bookmark' title='Permanent Link: IRC Defender 1.5 Released'>IRC Defender 1.5 Released</a></li>
<li><a href='http://www.irc-junkie.org/2007-08-28/irc-defender-back-under-development/' rel='bookmark' title='Permanent Link: IRC Defender Back Under Development'>IRC Defender Back Under Development</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-09/ircu-family-ircd-dos-exploit/' rel='bookmark' title='Permanent Link: IRCu Family IRCd DoS Exploit'>IRCu Family IRCd DoS Exploit</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Yesterday, news broke that there is an arbitrary code execution exploit within the still popular IRC security service IRC Defender which is, according to the reporter, being actively exploited.</p>
<p>The flaw is said to be within the InspIRCd link module for which a patched version exists, but according to the original post to the IRC-Security mailinglist there are more flaws within the InspIRCd link module and also within the UnrealIRCd link module.</p>
<p>The original poster on the mailinglist suggests to get rid of IRC Defender immediately and to replace it with something else (have a look at <a href="http://www.omega-services.org/">Omega Security Services</a>) and also to check for signs of recent intrusions which have taken place on or after 15th November. He also urges to look out for rogue entries in ~/.ssh/authorized_keys and look for suspicious processes.</p>
<p>So far, at least three networks seem to have been exploited due to this flaw &#8211; the highest profile victim so far seems to be the <a href="http://seclists.org/fulldisclosure/2011/Nov/266">hack of the AnonOps network</a> which also seems to have been possible due to that flaw &#8211; contrary to the rumored Anope 0-day.</p>
<p>Original post on the IRC-Security mailinglist is <a href="http://lists.irc-unity.org/mailman/private/irc-security/2011-November/014558.html">here</a> (needs registration).</p>
<p>Thanks to <em>alyx</em> for the tip etc!</p>
<p>The patched inspircd12.pm link module can be obtained from <a href="http://www.irc-junkie.org/wp-content/uploads/inspircd12.pm">here</a>.</p>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 27 November 2011 23:50:31 UTC by Digiprove certificate P207845" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P207845%26guid=o5fVCR3EukWCyhZp9WExoA" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--53CE6565E25BE293C8114203F6A22133455498BA826C22A29385D20C8533EA18--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1274&amp;md5=6494fcaa30453dfee96887c9cd183d11" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/">IRC Defender arbitrary code execution exploit</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-06-07/irc-defender-15-released/' rel='bookmark' title='Permanent Link: IRC Defender 1.5 Released'>IRC Defender 1.5 Released</a></li>
<li><a href='http://www.irc-junkie.org/2007-08-28/irc-defender-back-under-development/' rel='bookmark' title='Permanent Link: IRC Defender Back Under Development'>IRC Defender Back Under Development</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-09/ircu-family-ircd-dos-exploit/' rel='bookmark' title='Permanent Link: IRCu Family IRCd DoS Exploit'>IRCu Family IRCd DoS Exploit</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Mibbit has been compromised</title>
		<link>http://www.irc-junkie.org/2011-08-14/mibbit-has-been-compromised/</link>
		<comments>http://www.irc-junkie.org/2011-08-14/mibbit-has-been-compromised/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 10:15:11 +0000</pubDate>
		<dc:creator>Kottizen</dc:creator>
				<category><![CDATA[Clients]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Network Addons]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Mibbit]]></category>
		<category><![CDATA[Webchat]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1260</guid>
		<description><![CDATA[

On August 14 a cracker group claiming to be "hackers” named HTP broke into Mibbit, the popular web chat client for IRC. According to their temporarily “rescue” blog the break-in only affected their IRC network, their primary blog and their Wiki. NickServ passwords in clear text were released later the same day by the ...<p><a href="http://www.irc-junkie.org/2011-08-14/mibbit-has-been-compromised/">Mibbit has been compromised</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2009-12-23/mibbit-webchat-updates/' rel='bookmark' title='Permanent Link: Mibbit webchat updates'>Mibbit webchat updates</a></li>
<li><a href='http://www.irc-junkie.org/2006-06-26/cracker-creates-havoc-at-freenode/' rel='bookmark' title='Permanent Link: Cracker Creates Havoc at Freenode'>Cracker Creates Havoc at Freenode</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-23/atheme-inspircd-m_invisible-brouhaha/' rel='bookmark' title='Permanent Link: Atheme / InspIRCd m_invisible brouhaha'>Atheme / InspIRCd m_invisible brouhaha</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div>
<p>On August 14 a cracker group claiming to be &#8220;hackers” named HTP broke into Mibbit, the popular web chat client for IRC. According to their temporarily “rescue” blog the break-in only affected their IRC network, their primary blog and their Wiki. NickServ passwords in clear text were released later the same day by the HTP, as well as personal information regarding<a href="http://mibbitblog.blogspot.com/2011/08/blog-test-servers-compromised-update.html"> several staff members</a>. Both their IRC O-line passwords as well as their NickServ passwords, home addresses and phone numbers were published to the public via a range of file hosting services, and Pastebin.</p>
<p>Something perhaps even more concerning is that the group has revealed not only channel logs, but logs of private messages. <span style="text-decoration: line-through;">It appears like Mibbit has been logging what people have said in PM to each other over their network. According to official statements, this was only a test.</span> Some people have heard that Mibbit has been logging all messages going through their systems. Mibbit has never logged anything, unless a user wants to enable logging. The leaked message logs were captured by a staff member, and not by Mibbit&#8217;s system, according to official statements. While this is fully legal, the level of ethicality has been questioned.</p>
<p>The web IRC client that can be used to connect to almost any other network, which is what made them famous, has not been affected. It is operating normally.</p>
<p>All NickServ passwords were stored in plain text, and that raised a concern for those who are interested and engaged in enforcing security. According to staff member pottsi password hashing was not done because that would <a href="http://matilda.kottnet.net/IRC/references/mibbit-1.txt">“means sendpass and getpass would not work”</a>. Another staff member, Joshua, claimed that password hashing was not done because it was too much work to convert all passwords. This has however proven to be incorrect, at least if they used a plain copy of Anope. In Anope&#8217;s module database, there is a module called enc_switchover. It&#8217;s fairly easy to migrate from one encryption method, or none, to another, using <a href="http://matilda.kottnet.net/IRC/references/mibbit-2.txt">that module</a>. In addition to that, the <a href="http://modules.anope.org/index.php?page=view&amp;id=189">Anope module ns_resetpass</a> will allow users to reset their passwords despite encryption taking place.</p>
<p>Many people, especially IRC administrators, are now questioning Mibbit&#8217;s reliability and some are considering to block access from the web service, just like one of the largest networks, freenode, did a couple of years ago. This is mainly due to the question whether they log messages there too, which would go against many networks&#8217; policies.</p>
<p>The Mibbit team is now working very hard to bring all services back up again. At the time of writing, ChanServ and NickServ on their network is down and staff members are forced to use /samode if they need to get op. They advice everyone who had a NickServ account registered in April or earlier, this year, <a href="http://mibbitblog.blogspot.com/2011/08/blog-test-servers-compromised-update.html">to change password</a>.</p>
</div>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 14 August 2011 13:28:56 UTC by Digiprove certificate P164622" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P164622%26guid=z9ljIZpgj0azKg46yWAb4A" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--01C065937BFAF28F51B79B5FE0A41C87606F50A104A528621962C45A7295D250--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1260&amp;md5=1eeb7aa493bdcdb2d40d2df4441c0fa4" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-08-14/mibbit-has-been-compromised/">Mibbit has been compromised</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2009-12-23/mibbit-webchat-updates/' rel='bookmark' title='Permanent Link: Mibbit webchat updates'>Mibbit webchat updates</a></li>
<li><a href='http://www.irc-junkie.org/2006-06-26/cracker-creates-havoc-at-freenode/' rel='bookmark' title='Permanent Link: Cracker Creates Havoc at Freenode'>Cracker Creates Havoc at Freenode</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-23/atheme-inspircd-m_invisible-brouhaha/' rel='bookmark' title='Permanent Link: Atheme / InspIRCd m_invisible brouhaha'>Atheme / InspIRCd m_invisible brouhaha</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-08-14/mibbit-has-been-compromised/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>KVIrc 3.x and 4.x Remote Command Execution Vulnerability</title>
		<link>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/</link>
		<comments>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/#comments</comments>
		<pubDate>Sun, 01 Aug 2010 15:03:19 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Clients]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[KVIrc]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1194</guid>
		<description><![CDATA[All current versions of the KVIrc IRC client contain a remotely exploitable command execution vulnerability, including builds of KVIrc 4 from subversion up to revision 4692 as well as the older 3.x versions.

The bug, triggered by inserting carriage returns (r) into DCC GET commands, can be used to execute every command the IRCd understands ...<p><a href="http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/">KVIrc 3.x and 4.x Remote Command Execution Vulnerability</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-10-31/kvirc-340-irc-uri-handler-format-string-vulnerability-reloaded/' rel='bookmark' title='Permanent Link: KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded'>KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-12/bnc-289-remote-buffer-overflow/' rel='bookmark' title='Permanent Link: BNC 2.8.9 remote buffer overflow'>BNC 2.8.9 remote buffer overflow</a></li>
<li><a href='http://www.irc-junkie.org/2008-11-22/kvirc-342-uri-handler-in-combination-with-ie-exploitable/' rel='bookmark' title='Permanent Link: KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]'>KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>All current versions of the KVIrc IRC client contain a remotely exploitable command execution vulnerability, including builds of KVIrc 4 from subversion up to revision 4692 as well as the older 3.x versions.</p>
<p>The bug, triggered by inserting carriage returns (r) into DCC GET commands, can be used to execute every command the IRCd understands in the context of the user running the vulnerable client instance.</p>
<p>To check if your version is exploitable you can either take a look at the &#8220;About KVIrc&#8221; tab under &#8220;Help&#8221; and check the revision or execute the following command on IRC:</p>
<blockquote><p>/echo $version</p></blockquote>
<p>To make matters worse, whole channels can be exploited at once if they don&#8217;t have a mode set that disallows CTCPing them.</p>
<p>A quick workaround is to execute the following command, effectively preventing those &#8220;failed&#8221; DCC handshakes to be notified and disabling the bug:</p>
<blockquote><p>/option boolNotifyFailedDccHandshakes 0</p></blockquote>
<p>To see if you&#8217;ve already been exploited you can take a look in your server window and search for lines that look similar to these:</p>
<blockquote><p>[01:27:46] Processing DCC GET PRIVMSG #kvirc :I&#8217;m owned<br />
request from ATTACKER [ATTACKER@HOSTNAME] (DCC GETrPRIVMSG40#kvirc40:I&#8217;m40ownedr)<br />
[01:27:46] Unable to process the above request: Unknown DCC type &#8216;GET PRIVMSG #KVIRC :I&#8217;M OWNED &#8216;, Ignoring and notifying failure</p></blockquote>
<p>Updated builds of KVIrc are <a href="http://kvirc.net/?id=releases">available on their homepage</a> &#8211; some distributions also already have updated builds in their repository. If you can&#8217;t update because your distribution is not among the one with updated builds, the workaround helps to not fall prey to any possible attackers.</p>
<p><a href="https://svn.kvirc.de/kvirc/ticket/858">Original report on KVIrc bugtracker</a><br />
<a href="http://secunia.com/advisories/40727">Advisory on Secunia.com</a></p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 6 August 2010 18:11:18 UTC by Digiprove certificate P37679" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P37679;guid=CDJ3ZzZugEivFqyFMFSPLg" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--C5C934ECB28D4A7B4E495E8EB05A83B14E95196A9A9321F15C57DDF192029279--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1194&amp;md5=bc63ad3a9ca312d1fadfe6b4be21f40b" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/">KVIrc 3.x and 4.x Remote Command Execution Vulnerability</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-10-31/kvirc-340-irc-uri-handler-format-string-vulnerability-reloaded/' rel='bookmark' title='Permanent Link: KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded'>KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-12/bnc-289-remote-buffer-overflow/' rel='bookmark' title='Permanent Link: BNC 2.8.9 remote buffer overflow'>BNC 2.8.9 remote buffer overflow</a></li>
<li><a href='http://www.irc-junkie.org/2008-11-22/kvirc-342-uri-handler-in-combination-with-ie-exploitable/' rel='bookmark' title='Permanent Link: KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]'>KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</title>
		<link>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/</link>
		<comments>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/#comments</comments>
		<pubDate>Sat, 12 Jun 2010 10:24:23 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1034</guid>
		<description><![CDATA[Syzop of the UnrealIRCd project just posted an announcement on their mailinglist and forums that some versions of their IRCd have been compromised and had a backdoor added which went unnoticed for quite a while.

The first signs of the compromise have been traced back to November 2009 and Syzop writes that "Any Unreal3.2.8.1.tar.gz downloaded ...<p><a href="http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/">Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2007-05-13/syzop-resigns-his-position-on-the-unrealircd-project/' rel='bookmark' title='Permanent Link: Syzop resigns his position on the UnrealIRCd project'>Syzop resigns his position on the UnrealIRCd project</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2007-07-14/unrealircd-makes-a-drastic-change/' rel='bookmark' title='Permanent Link: UnrealIRCd Makes a Drastic Change'>UnrealIRCd Makes a Drastic Change</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><em>Syzop</em> of the UnrealIRCd project just posted an announcement on their mailinglist and forums that some versions of their IRCd have been compromised and had a backdoor added which went unnoticed for quite a while.</p>
<p>The first signs of the compromise have been traced back to November 2009 and <em>Syzop</em> writes that <em>&#8220;Any Unreal3.2.8.1.tar.gz downloaded BEFORE November 10 2009 should be  safe, but you should really double-check&#8221;</em>.</p>
<p><strong>Only the 3.2.8.1 source downloads (.tar.gz) are affected from this hack.</strong> Windows users, copies checked out from their CVS as well as users of older versions are safe and don&#8217;t need to check &#8211; everyone else should ensure they&#8217;re running a clean version of UnrealIRCd since the backdoor allows an attacker to issue and execute commands as the user the IRCd is running as, which essentially means your shell could easily compromised despite all other security measures.</p>
<p>Checking if your IRCd is one of those trojanized copies can easily be done either checking with md5sum or grep&#8217;ing the source for the backdoored code:</p>
<p>Run <em>&#8216;md5sum Unreal3.2.8.1.tar.gz&#8217;</em> on it and compare the resulting sum to the checksums below:<em> </em></p>
<blockquote><p>Backdoored version (BAD) is: 752e46f2d873c1679fa99de3f52a274d<br />
Official  version (GOOD) is: 7b741e94e867c0a7370553fd01506c66</p></blockquote>
<p>or use the command <em>&#8216;grep DEBUG3_DOLOG_SYSTEM include/struct.h&#8217;</em> from your Unreal3.2 directory &#8211; if this outputs 2 lines you&#8217;re running the trojanized version and need to get yourself a fresh and clean copy of the IRCd and recompile it since the compromised section is in the IRCds core and <em>&#8220;it is not possible to &#8216;clean&#8217; UnrealIRCd without a restart or through a  module&#8221;.</em></p>
<p><em>Syzop</em> writes that they have take precautions so such a compromise can never happen again and if it does that it&#8217;ll be noticed more quickly. They&#8217;re also planning to reimplement PGP/GPG signing of the releases which <em>&#8220;in practice (very) few people use&#8221;</em> but <em>&#8220;still [will] be useful for those people who do&#8221;</em>.</p>
<p>Closing his announcement he writes that he&#8217;d like to <em>&#8220;apologize about this security breach. We simply did not notice, but should have. We did not check the files  on all mirrors regularly, but should have. We did not sign releases  through PGP/GPG, but should have done so. Hope you&#8217;ll all continue to support UnrealIRCd&#8221;</em>.</p>
<p>The full announcement can be read <a href="http://forums.unrealircd.com/viewtopic.php?t=6562">here</a> and the advisory can be found <a href="http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt">here</a>.</p>
<p><strong>[Update]:</strong> Servers running the trojanized versions of UnrealIRCd should be updated as soon as possible since HD Moore, the creator of the Metasploit exploitation framework, already <a href="http://www.metasploit.com/redmine/projects/framework/repository/revisions/9503/entry/modules/exploits/unix/irc/unreal_ircd_3281_backdoor.rb">released a module for it</a> &#8211; but even without that the security hole is really simple to exploit.</p>
<p>Also, <a href="http://www.xzibition.com/fix-unreal.sh">here is a .sh script</a> that might help you in the upgrade process &#8211; at least one user on the UnrealIRCd forums claimed it worked for him (although no kind of guarantee is given neither by the author nor by me).</p>
<p><strong>[Update 2]:</strong> <em>Syzop</em> just <a href="http://forums.unrealircd.com/viewtopic.php?t=6563">posted a follow-up</a> in which he writes that their releases are <em>&#8220;from now on signed with GnuPG (PGP) again&#8221;</em>.</p>
<p><strong>[Update 3]:</strong> In an email to the UnrealIRCd mailinglist, <em>Syzop</em> elaborates on the GPG/PGP signing and says that there will be instructions on how to verify the key when you download the future releases. He also <a href="http://forums.unrealircd.com/viewtopic.php?f=1&amp;t=6566">goes into some detail which precautions the team has taken</a> that such an incident <em>&#8220;will never ever happen again&#8221;</em>. He rightfully criticizes certain news-outlets that claimed it was the fault of the Open Source model and even Linux (*cough*ZDNet*cough*) &#8211; some websites even confused the IRCd with EPIC softwares first-person shooter Unreal Tournament.</p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 14 June 2010 20:21:14 UTC by Digiprove certificate P20120" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P20120;guid=twt_eBsiyUesYmzK7R2MoQ" style="text-decoration:none" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0"/><span style="font-family: Tahoma, MS Sans Serif; font-size:11px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--7C9D003388986CD7761FB99CD0CE639CD8D75C1BB42607266C0B70A297CEE865--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1034&amp;md5=deab499b17e98612f6ade2d4b0eef151" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/">Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2007-05-13/syzop-resigns-his-position-on-the-unrealircd-project/' rel='bookmark' title='Permanent Link: Syzop resigns his position on the UnrealIRCd project'>Syzop resigns his position on the UnrealIRCd project</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2007-07-14/unrealircd-makes-a-drastic-change/' rel='bookmark' title='Permanent Link: UnrealIRCd Makes a Drastic Change'>UnrealIRCd Makes a Drastic Change</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Researchers develop &#8220;HoneyBot&#8221;, Social Engineer IRC Users automatically</title>
		<link>http://www.irc-junkie.org/2010-06-11/researchers-develop-honeybot-social-engineer-irc-users-automatically/</link>
		<comments>http://www.irc-junkie.org/2010-06-11/researchers-develop-honeybot-social-engineer-irc-users-automatically/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:17:32 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[HoneyBot]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1025</guid>
		<description><![CDATA[Researchers of the TU Wien (Vienna University of Technology, Austria) achieved a stunning - and at the same time scary - 76,1% click rate on possibly malicious links in conversations that took place on IRC using an automated social-engineering software dubbed "HoneyBot".

Their new approach to automated social engineering ("ASE") does not rely on artificial ...<p><a href="http://www.irc-junkie.org/2010-06-11/researchers-develop-honeybot-social-engineer-irc-users-automatically/">Researchers develop &#8220;HoneyBot&#8221;, Social Engineer IRC Users automatically</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2006-05-10/girls-receive-up-to-25-times-more-malicious-chat/' rel='bookmark' title='Permanent Link: Girls Receive Up To 25 Times More Malicious Chat'>Girls Receive Up To 25 Times More Malicious Chat</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-16/beat-them-at-their-own-game/' rel='bookmark' title='Permanent Link: Beat Them at Their Own Game'>Beat Them at Their Own Game</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Researchers of the TU Wien (Vienna University of Technology, Austria) achieved a stunning &#8211; and at the same time scary &#8211; 76,1% click rate on possibly malicious links in conversations that took place on IRC using an automated social-engineering software dubbed <strong><em>&#8220;HoneyBot&#8221;</em>.</strong></p>
<p>Their new approach to automated <a href="http://en.wikipedia.org/wiki/Social_engineering_%28security%29">social engineering</a> (&#8220;ASE&#8221;) does not rely on artificial conversations from an AI but instead used the bot to relay messages between humans, effectively avoiding detection according to what is commonly referred to as &#8220;Turing Test&#8221; in which humans assess if they can tell apart that they are talking to a human or a computer program of sorts. Previous generations of such bots used an AI called &#8220;Artificial Intelligence Markup&#8221; to engage in conversations with a much lower success rate: Users where able to spot 80% of the bots after exchanging only 3 messages with them.</p>
<p>HoneyBot acts as a &#8220;Man-in-the-middle&#8221; and relays messages between two unsuspecting users which seem to have perfectly normal conversation going on:</p>
<blockquote><p>bot → Alice: <em>Hi!</em><br />
Alice → bot: <em>hello</em><br />
bot → Carl: <em>hello</em><br />
Carl → bot: <em>hi there, how are you?</em><br />
bot → Alice: <em>hi there, how are you?</em><br />
Alice → bot: <em>&#8230;</em></p></blockquote>
<p>But that&#8217;s not all &#8211; the bot is capable of influencing the ongoing conversation by <em>&#8220;dropping, inserting, or modifying messages&#8221;</em> and the researchers assert that <em>&#8220;if links (or questions) are inserted into such a conversation, they will seem to originate from a human user&#8221;</em> and therefore the click-probability will be <em>&#8220;higher than in artificial conversation approaches&#8221;.</em></p>
<p>The really sophisticated bot is able to determine the gender of the persons it is talking to and makes on-the-fly adjustments to all relayed messages so <em>&#8220;Hello, i&#8217;m a guy&#8221;</em> becomes <em>&#8220;Hello, i&#8217;m a lady&#8221;</em> when its gender-detection algorithm determined that the conversational partner likely is male. Insertion of links also has some level of sophistication &#8211; instead of just dumping a link into the conversation and hoping for a click, the bot has 3 options for doing so:</p>
<ul>
<li><span style="text-decoration: underline;">Insert a random link:</span> Along with a generic message a link is sent to the other user if they have been engaged in a conversation for a minimum number of messages</li>
</ul>
<ul>
<li><span style="text-decoration: underline;">Keywords:</span> Reply with links to keywords such as &#8220;ASL?&#8221;</li>
</ul>
<ul>
<li><span style="text-decoration: underline;">Replacement link:</span> Questions already containing links to sites such as YouTube are replaced with own links and therefore look most natural since the question was composed by a human. Also, the bot can inject probing questions to steer the conversation into a certain direction.</li>
</ul>
<p>Trying to be as stealthy and sneaky as possible, the bot never contacts users with <em>&#8220;administrative privileges&#8221;</em> but replys to private messages by such, although it will never inserts links or questions into those conversations. Additionally, a random delay is used when &#8220;typing&#8221; messages to make detection even harder.</p>
<p>Aware that what they have created is a whole can of worms when used unethically, the researchers made sure that personally identifiable data such as eMail and IM addresses are never relayed and links sent in conversations are filtered if they&#8217;re not going to be replaced by HoneyBot.</p>
<p>The channels monitored by the bot where 2 dating and one generic chat channel of  which neither the channels nor the network have been named in the research paper.</p>
<div id="attachment_1028" class="wp-caption aligncenter" style="width: 407px"><a href="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Monitoring_Statistics.png"><img class="size-full wp-image-1028" title="HoneyBot Monitoring Statistics" src="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Monitoring_Statistics.png" alt="HoneyBot Monitoring Statistics" width="397" height="98" /></a><p class="wp-caption-text">HoneyBot Monitoring Statistics</p></div>
<p>When talking about the ethics, the researchers conclude that they&#8217;re well within the guidelines set forth by the IRB (Institutional Review Board) based on similar researches and also got a nod from the legal department of the university. They chose to not inform users before the experiment since this would most likely have influenced the results as <em>&#8220;users that are aware of participating in a study are likely to be more cautious than usual&#8221;</em> and say that they <em>&#8220;carried out the study only with users that responded to our messages and thereby accepted talking to the bot (i.e., stranger)&#8221;</em> and emphasize that there were no <em>&#8220;ongoing conversations intruded&#8221;</em> by them. Also they note that all data collected <em>&#8220;although largely anonymous&#8221;</em> has been deleted after the <em>&#8220;evaluation phase&#8221;</em>.</p>
<p>With 3 seperate bots &#8211; a &#8220;periodic spam&#8221; bot, a private-message spam bot and a keyword spam bot &#8211; they evaluated the likelyhood of users clicking on links, the results can be seen in the below table:</p>
<div id="attachment_1029" class="wp-caption aligncenter" style="width: 380px"><a href="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Monitoring_Statistics2.png"><img class="size-full wp-image-1029" title="HoneyBot Monitoring Statistics - Clicked Links" src="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Monitoring_Statistics2.png" alt="HoneyBot Monitoring Statistics - Clicked Links" width="370" height="101" /></a><p class="wp-caption-text">HoneyBot Monitoring Statistics - Clicked Links</p></div>
<p>Altogether, only 1.7% of the online users could be enticed into clicking a link by those 3 &#8220;classic&#8221; bot types and the bot only got to post 8 links on the Chat channel before it was banned by a channel op.</p>
<p><span style="text-decoration: underline;"><strong>Enter HoneyBot:</strong></span></p>
<p>The longest conversation HoneyBot had took a staggering 2 and a half hours with 325 messages transmitted and it achieved a median chat time of <em>&#8220;longer than 30 minutes&#8221;.</em></p>
<p>Out of the 3 possible URLs the bot has sent &#8211; broken down in IP, TinyURL and a MySpace link &#8211; TinyURL links where the most clicked about which the researchers rightfully say is counter-intuitive since <em>&#8220;TinyURLs can hide arbitrary URLs whereas a MySpace link always leads to a profile&#8221;.</em></p>
<div id="attachment_1030" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Clicked_Links_Breakdown.png"><img class="size-medium wp-image-1030" title="HoneyBot - Clicked Links Breakdown" src="http://www.irc-junkie.org/wp-content/uploads/HoneyBot_Clicked_Links_Breakdown-300x111.png" alt="HoneyBot - Clicked Links Breakdown" width="300" height="111" /></a><p class="wp-caption-text">HoneyBot - Clicked Links Breakdown</p></div>
<p>Furthermore, the MySpace links the bot sent out had to be reassembled by the user because a space character was inserted into the URL and the researchers said they&#8217;re <em>&#8220;surprised that this reassembly has happened at all&#8221;.</em></p>
<p>It should not go unmentioned that the same type of research was conducted on Facebook where they created one male and one female profile and tried to befriend users of the opposite sex. The new friends, if successful in bootstrapping a conversation, then tried to make them click on the same links as the IRC bot. And even though 4 out of 10 people clicked them, the researchers believe that the attack could have been way more successful if they went as far as cloning profiles, befriend users from those and relay messages from cloned to authentic profiles.</p>
<p>As can be seen from the Facebook example, this kind of attack is not limited to IRC exclusively but can be adopted to a whole host of so-called Social-networking sites and systems.</p>
<p>Mitigation of these social engineering threats is not easy and there is no fast and hard measure that can prevent all of them, however raising awareness is one way to make users more alert to it and is what the researchers tried to achieve: <em>&#8220;We hope that <a href="http://seclab.tuwien.ac.at/papers/autosoc-leet2010.pdf">this paper</a> will contribute to this process.&#8221;</em></p>
<p><em>In <span style="text-decoration: line-through;">Soviet Russia</span> Vienna bots social engineer <strong>you!</strong></em></p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 11 June 2010 14:17:35 UTC by Digiprove certificate P19761" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P19761;guid=4m-Rk2_o2kWFwfvCmccFgg" style="text-decoration:none" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0"/><span style="font-family: Tahoma, MS Sans Serif; font-size:11px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--C6FFF5802C467BA26A0682AC93C3BF910608BDA5845F27AFF6622B6145433569--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1025&amp;md5=c7df67292a0a9440129a75b414398a03" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-06-11/researchers-develop-honeybot-social-engineer-irc-users-automatically/">Researchers develop &#8220;HoneyBot&#8221;, Social Engineer IRC Users automatically</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2006-05-10/girls-receive-up-to-25-times-more-malicious-chat/' rel='bookmark' title='Permanent Link: Girls Receive Up To 25 Times More Malicious Chat'>Girls Receive Up To 25 Times More Malicious Chat</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-16/beat-them-at-their-own-game/' rel='bookmark' title='Permanent Link: Beat Them at Their Own Game'>Beat Them at Their Own Game</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-06-11/researchers-develop-honeybot-social-engineer-irc-users-automatically/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

