|
|
| Author |
Message |
CyberWar none

Joined: 13 Jun 2006 Posts: 15
|
Posted: Jul 28, 2006 1:54am Post subject: UnrealIRCD 3.2.4 Extremely Danger! |
|
|
We have the old version from Unreal 3.2.4
This version has a Danger bug for Script kids recently someone got itself the oper status on my irc. after: i write with him and it write. " I get entrance on each IRC with this Exploit "
afterwards i took the new version
Please Admins Update
From 3.2.4 or older to 3.2.5 |
|
| Back to top |
|
 |
Willaim Lurker

Joined: 27 Jun 2003 Posts: 227 Location: IRC
|
Posted: Jul 28, 2006 5:31pm Post subject: |
|
|
| I assume you sent this to the UnrealIRCD developers before posting here. |
|
| Back to top |
|
 |
FBI Guru

Joined: 19 Aug 2005 Posts: 1494 Location: Federation Of Bored IRC'ers
|
Posted: Jul 28, 2006 7:35pm Post subject: Re: UnrealIRCD 3.2.4 Extremely Danger! |
|
|
| CyberWar wrote: | We have the old version from Unreal 3.2.4
This version has a Danger bug for Script kids recently someone got itself the oper status on my irc. after: i write with him and it write. " I get entrance on each IRC with this Exploit "
afterwards i took the new version
Please Admins Update
From 3.2.4 or older to 3.2.5 |
Theres reason why theres updates......
Gotta always update  |
|
| Back to top |
|
 |
CyberWar none

Joined: 13 Jun 2006 Posts: 15
|
Posted: Jul 29, 2006 1:43am Post subject: |
|
|
Willaim we have already announced but the UnrealIRCD Devs. have only laughed and i became zlined
I thank you all UnrealIRCD devs. us there sooooo much helped
FBI yea you are right  |
|
| Back to top |
|
 |
Kelsey23 none

Joined: 27 Feb 2006 Posts: 33
|
Posted: Jul 29, 2006 11:40am Post subject: |
|
|
| CyberWar wrote: | Willaim we have already announced but the UnrealIRCD Devs. have only laughed and i became zlined
|
Sounds like the Unreal team... |
|
| Back to top |
|
 |
SATAN-HHH Eleet

Joined: 29 Nov 2003 Posts: 838 Location: Texas
|
Posted: Jul 30, 2006 6:28pm Post subject: |
|
|
| This is one of the things that turns me off to Unreal Ircd. |
|
| Back to top |
|
 |
PingBad Guru

Joined: 05 Feb 2005 Posts: 1982 Location: New Zealand
|
Posted: Jul 30, 2006 10:11pm Post subject: |
|
|
| to, or from? |
|
| Back to top |
|
 |
SebasMiles none

Joined: 22 Nov 2005 Posts: 30
|
Posted: Jul 31, 2006 7:33am Post subject: |
|
|
| Its very simple, when a new update comes out, unless you really need to upgrade I suggest you wait a bit, probably around 1 month before upgrading. This is what happened with that version of unreal, there was a first release and it had a bug(hey it happens) and then they released a new version of 3.2.4, As an admin you have to try and keep track of this, instead of keeping a buggy version for over 5 months (the bug was discovered soon after the release, and that was a LONG time ago). |
|
| Back to top |
|
 |
upinsmoke Newbie

Joined: 01 Mar 2004 Posts: 61 Location: pennsylvania
|
Posted: Jul 31, 2006 2:59pm Post subject: |
|
|
the 3.2.4 re-release was because of the ? wildcard not working. not because some script kiddie could get oper status on any unrealircd net
http://www.unrealircd.com/324rerelease.txt |
|
| Back to top |
|
 |
SATAN-HHH Eleet

Joined: 29 Nov 2003 Posts: 838 Location: Texas
|
Posted: Jul 31, 2006 5:04pm Post subject: |
|
|
| PingBad wrote: | | to, or from? |
from, apparently was tired when i typed that |
|
| Back to top |
|
 |
Tranqerr none

Joined: 24 Mar 2005 Posts: 11
|
Posted: Aug 05, 2006 7:11am Post subject: |
|
|
The only way someone is able to gain oper level at 3.2.4 is by having a very wild host set in the operblock, a common ircop nick and some very often used password.
Its not a error/bug/mistake in the unreal versions... Why did you get yourself klined....wasnt it advertising other networks? Not to mention being an ass in the channel?
Heres my advise: use complete host or ident/isp in the operblock, use a non irc related nickname and some passsword that isnt "qwe123" or "password"...
PS; Did you finally checked your ircd.log to see how often he actually attempted to oper up? |
|
| Back to top |
|
 |
m00c0w none

Joined: 07 Dec 2005 Posts: 28
|
Posted: Aug 05, 2006 9:35am Post subject: |
|
|
well - i for one bet that he didnt check a log, yet he is running around screaming "FIRE FIRE"...
to me it is completely unfounded BS, otherwise you'd see many many more posts like this from messed up networks |
|
| Back to top |
|
 |
SATAN-HHH Eleet

Joined: 29 Nov 2003 Posts: 838 Location: Texas
|
Posted: Aug 05, 2006 10:20am Post subject: |
|
|
| True. Why people still use *@* in their oper lines leaves me dumbfounded. That is just asking to have your network messed with. I understand some people have ever-changing hosts, but there's still ways using part host and wildcard to do it without the "all" mask, such as opme@*.comcast.net or something like that. People just love rolling the dice I guess. |
|
| Back to top |
|
 |
|