General Topics

Attention Mirc Users

1 post

Post a reply

Attention Mirc Users

#1
mIRC DCC Exploit

updated Mon Oct 13 01:21:32 EDT 2003

Main Information and Fix

Starting Oct 12, 2003, an exploit was used to crash many people's mIRC clients. All versions from 6.0 thru the recently released 6.11 are affected. (It does not appear to affect version 5.91 or earlier.) The exploit involves a type of DCC command which can be sent to any person or channel, no matter what your DCC options are. (DCC is used to trade files or for DCC chat.) The author of mIRC has been notified, presumably an official fix will be forthcoming "soon" but that is up to him. In the meantime, please don't clamor for more information, everything we are at liberty to say is here.

For now, the only known fix is to ignore all DCC requests entirely. Just type the following command, on a new line by itself in any chat window, beginning with the slash character:

/ignore -wd *

(We don't advise downgrading to 5.x, since those have known exploits and multi-server doens't work. Do you really need warez/porn that badly that you can't ignore DCCs a few days? Err, don't answer that.)

This page will be updated as necessary. Check EFnet #mIRC topic (use /raw list #mIRC if you cannot join) for updates too. The information was contributed by EFnet helpers from many sources, working together in harmony without ego or drama, who knew. It is not an official message from the author of mIRC.

The following is for geeks, most people can stop reading. :-)

Other Information

Is this the /userhost bug? No, that was fixed in 6.11. It's also not the DCC resume bug or any other old bug. This is something totally different, affecting every version of 6.* including the current 6.11 - yes, we tested every single one.

How can I trust you? What does that /ignore command do? To learn what it does, type: /help /ignore (again on a new line by itself). It's just a command to ignore DCCs, you can turn it off any time by /ignore -rwd * The command is also in the topic of #mIRC on any large network such as EFnet, IRCnet, DALnet, etc.

But how do I download files now? If you really want, you can except certain trusted people from the ignore: first do /ignore -wd * then /ignore -x nickname where nickname is the trusted exception. Of course once you do that, that nickname can hit you with that attack so don't come crying if you fall for that trick.

How does the exploit work? We understand that you are curious, and that security through obscurity is dumb. Now you need to understand this: If we describe the exploit in detail, we are basically letting anybody attack countless innocent people who haven't set the /ignore command yet. Your curiosity will just have to wait. A simple, harmless temporary fix exists, so there is no compelling common good that demands the immediate release of all details. We're not telling, so stop asking please.

Can the attack do more than crash me? Can they make me issue arbitrary commands? The attack can be used to crash you to take your nick, or crash all ops in a channel for a takeover. Beyond that nobody knows. Assume the worst to be safe.

Can I stop the exploit with a remote to halt CTCPs or some DCC options? Apparently not, the /ignore -wd * is the only way we know. You are vulnerable even if you set a remote to halt CTCPs or ignore all DCC sends in the options.

Is this an actual attack or just some theoretical thing? Hundreds of people got crashed already, the attack is known to many people. On the other hand, for most people a mIRC crash isn't the end of the world. Assess the risk yourself.

Source

Return to “General Topics”