www.IRC-Junkie.org Forum Index
Norton Internet Security DoS Vulnerability
Goto page 1, 2??Next
?
Post new topic???Reply to topic ???www.IRC-Junkie.org Forum Index -> News
View previous topic :: View next topic ?
Author Message
Asmo
Site Admin


Joined: 26 Oct 2004
Posts: 675
Location: Undernet

PostPosted: Fri Feb 24, 2006 10:06 am?? ?Post subject: Norton Internet Security DoS Vulnerability Reply with quote

"I'm not quite sure what the problem is with this, but I'm told its a problem with norton personal firewall", this URL starts which have been going around IRC as a running fire.

Users who make use of the Norton Internet Security package will be disconnected from their IRC server when they receive any message, be it channel, private, notice when they contain the words startkeylogger or stopkeylogger.

These two commands are part of the list of commands for Spybot for which Norton released new code which introduced this bug.

Some users are going around populated channels now pasting the two commands. Some networks, like EFnet are acting against such users with kills, as we can see from the publicly available list of last executed kills and their reasons.
_________________
Asmo

webmaster www.IRC-Junkie.org
Back to top
View user's profile Send private message Visit poster's website



Delta



Joined: 11 Feb 2005
Posts: 10

PostPosted: Fri Feb 24, 2006 4:48 pm?? ?Post subject: Reply with quote

Supposidly at least 1 channel on rizon put it in their topic, so any time someone did /list, it would pick it up, heh

~Francisco
Back to top
View user's profile Send private message
Thunderguy



Joined: 24 Feb 2006
Posts: 1

PostPosted: Fri Feb 24, 2006 7:08 pm?? ?Post subject: Reply with quote

Is it just on Irc or anywhere? You have it in plaintext in the html code on your main page, I hope everyone that goes to www.Irc-Junkie.org and has Norton doesn't get disconnected.
Back to top
View user's profile Send private message
Asmo
Site Admin


Joined: 26 Oct 2004
Posts: 675
Location: Undernet

PostPosted: Fri Feb 24, 2006 7:34 pm?? ?Post subject: Reply with quote

I'll be laughing myself in a 90 degree angle if that is happening =D

All praise to Norton for making such code public in such a widespread and money-making package! ;)
_________________
Asmo

webmaster www.IRC-Junkie.org
Back to top
View user's profile Send private message Visit poster's website
Delta



Joined: 11 Feb 2005
Posts: 10

PostPosted: Sat Feb 25, 2006 3:51 am?? ?Post subject: Reply with quote

It seems to only happen if it comes over port 6667 since the spybot virus connected only over that port

~Francisco
Back to top
View user's profile Send private message
phrozen77



Joined: 11 Nov 2004
Posts: 20

PostPosted: Sat Feb 25, 2006 9:52 am?? ?Post subject: Reply with quote

roflmao Razz


spamfilter added - now i wonder how many actually try this lololol
Back to top
View user's profile Send private message
Lame_nick



Joined: 03 Feb 2006
Posts: 4
Location: Norway

PostPosted: Sun Feb 26, 2006 3:05 am?? ?Post subject: Reply with quote

This is kinda stupid of Norton, this just had to be exploited some day...
Yeah, this does only work on IRC.
Delta, I think the spybot worm may connect to 6667-7000.
Back to top
View user's profile Send private message Visit poster's website
SpaceCat



Joined: 26 Feb 2006
Posts: 1
Location: irc.omegairc.org #Slackware, #Newbies

PostPosted: Sun Feb 26, 2006 5:17 pm?? ?Post subject: Reply with quote

lollllllllllll bullshhhhh..
(08:11:16:am) (CatfishMan) i have norton internet security 2005
(08:11:25:am) (W-T) startkeylogger
(08:11:30:am) (CatfishMan) nothing happens

Plus a company like symantec wouldnt screw up with a so easy to see bug so nvm lol
_________________
irc.omegairc.org #Galaxy
Back to top
View user's profile Send private message
Lame_nick



Joined: 03 Feb 2006
Posts: 4
Location: Norway

PostPosted: Sun Feb 26, 2006 5:36 pm?? ?Post subject: Reply with quote

SpaceCat, you really think this is bullsh*t? It works. I know it does. So does many others. Maybe that guy didn't have the firewall activated or something?
Back to top
View user's profile Send private message Visit poster's website
Mentality



Joined: 28 Oct 2004
Posts: 32

PostPosted: Sun Feb 26, 2006 8:29 pm?? ?Post subject: Reply with quote

"Plus a company like symantec wouldnt screw up with a so easy"

Umm, yes they would. This isn't the first time this has happened. I remember a couple of years ago (I think it affected NAV 2003), if you did a /list on DALnet, people had put a certain virus string in the topic of a channel. Once the /list had processed that channel name, NAV would pop up saying that your computer was infected. I saw this myself, it happened on my computer. DALnet IRC Operators then changed the topic if I recall correctly.

Since when have big companies not been prone to fuck ups? Have you ever used Windows Update?

Regards,
_________________
Mentality/Chris
Back to top
View user's profile Send private message Send e-mail
DreamGirl



Joined: 27 Feb 2006
Posts: 1

PostPosted: Mon Feb 27, 2006 2:45 pm?? ?Post subject: Reply with quote

Big thanks for this news!! With all blocks in place this has spared many much irritation Smile
_________________
Together we make IRC work, one smiling face at a time Smile
Back to top
View user's profile Send private message Visit poster's website
phrozen77



Joined: 11 Nov 2004
Posts: 20

PostPosted: Mon Feb 27, 2006 6:12 pm?? ?Post subject: Reply with quote

Mentality wrote:
Umm, yes they would. This isn't the first time this has happened. I remember a couple of years ago (I think it affected NAV 2003), if you did a /list on DALnet, people had put a certain virus string in the topic of a channel. Once the /list had processed that channel name, NAV would pop up saying that your computer was infected. I saw this myself, it happened on my computer. DALnet IRC Operators then changed the topic if I recall correctly.


this was, if im not mistaken,

Quote:

echo y | format c:


Razz
Back to top
View user's profile Send private message
Asmo
Site Admin


Joined: 26 Oct 2004
Posts: 675
Location: Undernet

PostPosted: Fri Mar 03, 2006 8:37 am?? ?Post subject: Reply with quote

Article in the Washington Post.
_________________
Asmo

webmaster www.IRC-Junkie.org
Back to top
View user's profile Send private message Visit poster's website
Asmo
Site Admin


Joined: 26 Oct 2004
Posts: 675
Location: Undernet

PostPosted: Sat Mar 04, 2006 9:50 am?? ?Post subject: Reply with quote

And Symantec released a fix now :)

BTW, I see all newspapers claiming the Washington Post article as the source, but they did not reported about it 2 days or so after IRCJunkie did. Darn, even Slashdot did! Normally they would be slashdotting me... Ah well ;)
_________________
Asmo

webmaster www.IRC-Junkie.org
Back to top
View user's profile Send private message Visit poster's website
phrozen77



Joined: 11 Nov 2004
Posts: 20

PostPosted: Sat Mar 04, 2006 5:01 pm?? ?Post subject: Reply with quote

the question is, if you really want to be slashdotted..

i read an article quite a while ago and after that i wasnt too sure if _i_ still would want that....

in summary, it also has negative effects, just like getting your network into servers.ini Wink
Back to top
View user's profile Send private message
Display posts from previous: ??
Post new topic???Reply to topic ???www.IRC-Junkie.org Forum Index -> News All times are GMT + 1 Hour
Goto page 1, 2??Next
Page 1 of 2

?
Jump to:??
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB ? 2001, 2002 phpBB Group

Debt Consolidation | Internet Advertising | Movies download | Collaboration Software | Magic the Gathering