Whats up with this? - Printable Version -Shoutbox (https://shoutbox.menthix.net) +-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58) +--- Forum: Messenger Plus! for Live Messenger (/forumdisplay.php?fid=4) +---- Forum: WLM Plus! General (/forumdisplay.php?fid=23) +----- Thread: Whats up with this? (/showthread.php?tid=28348) Whats up with this? by GiantSpider on 07-08-2004 at 03:09 PM
quote: Eh? RE: Whats up with this? by Mnjul on 07-08-2004 at 03:30 PM
Patchou hasn't spoken a word, to my acknoledgement, and timothy didn't give more detail too. But this is what I am going to say: RE: Whats up with this? by Anubis on 07-08-2004 at 03:36 PM Yeah. I am aware of this bug, there was a thread about it yesterday...Surprisingly simple to do...I'm not going to say how because I want to keep this under-wraps as well but lets just say be careful about what's in people's screen names... RE: Whats up with this? by GiantSpider on 07-08-2004 at 04:04 PM Were you talking to me Mnjul? RE: Whats up with this? by Jolo on 07-08-2004 at 04:06 PM
I'm very scared. This is serious. RE: Whats up with this? by GiantSpider on 07-08-2004 at 04:08 PM Well I assume this problem is controlled via a remote user so when you use internal cmd's I think you should be ok. RE: RE: Whats up with this? by Sunshine on 07-08-2004 at 04:12 PM
quote: I agree, info like that shouldnt be posted onhere...it's encouraging ppl ta abuse it (just like telling a person how ta hack) bugs like that should be reported to Patchou directly so he can take actions. Mnjul, did u tell Patchou what was in the posts..so he can do something bout the exploit? RE: Whats up with this? by Jolo on 07-08-2004 at 04:13 PM As a preventing action, I have removed the (!N) tag from the openConvo plug-in. RE: Whats up with this? by Mnjul on 07-08-2004 at 04:15 PM I mailed Patchou about this..but don't worry, I think Timothy had already done so when he posted on mess.be And again, don't worry, Patchou is enough trustworthy so, just wait for an update very soon RE: RE: Whats up with this? by Sunshine on 07-08-2004 at 04:24 PM
quote: Thanks Mnjul, better e-mailed twice about it than not at all. I'll take good notice of ppl's nicks till then. RE: Whats up with this? by timothy on 07-08-2004 at 04:31 PM
I already mailed him before, but since I have the idea it didn’t got through I’ve posted it <somewhere> here. (mods please remove that topic). RE: Whats up with this? by Patchou on 07-08-2004 at 04:38 PM
What?!?!? what is the meaning of the joke? There is absolutely nothing to be worried about and there's nothing to fix. I never got any mail from Timothy about this, else, I would have replied the same thing I'm going to reply now. Here is what they seem to be talking about: RE: Whats up with this? by timothy on 07-08-2004 at 04:41 PM
quote: Read the post bitte, I allready mailed you 2 days ago, But, the reason Im concerned about is that people use this to trick other people. Ill PM you with the full details patchou, and Ill remove the post from mess.be, RE: Whats up with this? by Patchou on 07-08-2004 at 04:48 PM
I never got any mail from you Tim, that's unfortunate . Well, if we're talking about the same thing, at least I'm sure that there's nothing to worry about. As I sais in my previous post, even if the user did some kind of copy past, he would still have to select Open and accept the security warning displayed by Internet Explorer. I see no problem here. Any program allows you to run something, at least from an explorer file selection window. That's not a security problem, that's just a fact . RE: Whats up with this? by timothy on 07-08-2004 at 04:53 PM
I PM-ed you, it has nothing to do with downloading of files, its about executing remote commands on some-one else’s computer, all posts and messages about it are removed RE: Whats up with this? by Patchou on 07-08-2004 at 04:58 PM If you PMed me you should have gotten a message from the forum saying that I rarely reply to PMs as I receive too many, sorry about that . As for executing remote commands, I see what you mean, but there's nothing harmful that could be done this way. If a user types (!N) alone after being asked by someone that has "/nick Sadam" as name and wonders why his name because Sadam, it's not the end of the world . Again, the same user could ask the same guy to download a file and execute it, which woud be far more dangerous. RE: Whats up with this? by timothy on 07-08-2004 at 05:04 PM
yeah, but the /run command also executes from a nick.... RE: Whats up with this? by KeyStorm on 07-08-2004 at 05:14 PM
Hm, I'm starting to see the point. It is rather social engineering If I'm not wrong. But it's very likely to happen to many people who don't know about what dangerous files they may accept or whan certain commands can do. quote:Sadly true... RE: Whats up with this? by timothy on 07-08-2004 at 05:22 PM The problem is, those programs are allready on the other user`s computer, system tools etc. And now it just executes without a warning this way, RE: Whats up with this? by Zero1 on 07-08-2004 at 05:27 PM
Patchou, i agree that changing someone elses nick isnt exactly 'dangerous', But all of the Messenger Plus! commands are available to these people to use - people wanted to find a way of getting an IP over messenger, now they have it. RE: Whats up with this? by KeyStorm on 07-08-2004 at 05:29 PM
If we avoided tags to imply the hability to run inner commands we would stop some plugins and home-made aliases to work, so I don't see any other solution than warning when system files or executables are going to be runned. RE: Whats up with this? by timothy on 07-08-2004 at 05:32 PM The execution by short codes isn’t the problem, the execution with (!N) should be prohibited. This one should only be intended to display some-one`s nickname... RE: Whats up with this? by Zero1 on 07-08-2004 at 05:33 PM Why not sterilise the (!N) command? this is the only one that would need modifying as its the only one that a remote attacker could use. For example in PHP there is a command that lets you stop variables being executed as variables and just shown how they are. Couldnt this be possible with MP3? RE: Whats up with this? by KeyStorm on 07-08-2004 at 05:45 PM
<?PHP RE: Whats up with this? by Zero1 on 07-08-2004 at 05:48 PM
Yes, the addslashes command was what i was using as an example RE: Whats up with this? by KeyStorm on 07-08-2004 at 05:57 PM
or worse: after they tell you to type (!N) they could change their nicknames so it looks less suspicious. quote:lol, obviously. I still think the warning methos would be the best and most easy way around it. But I can't see a use for parsing nicknames, so killing that would also be a solution RE: Whats up with this? by timothy on 07-08-2004 at 06:04 PM
Personally, the only reason why the /run command would be left in there is because you want a quick way to execute something without using your mouse.... ( windows key + r is a great alternative ). RE: Whats up with this? by KeyStorm on 07-08-2004 at 06:44 PM
quote: I rather meant aliases The use for some plugins would need to parse anything inside a tag. If we disabled that some would not work. I guess, RE: Whats up with this? by lopardo on 07-08-2004 at 07:06 PM
I would suggest this:
But it's up to Patchou whether or not to do it RE: Whats up with this? by GiantSpider on 07-08-2004 at 07:06 PM So the threat is actually there? That's some damn buisness. So in laymens (simple) terms what is the problem? RE: Whats up with this? by lopardo on 07-08-2004 at 07:12 PM The problem is that the contents of (!N) are parsed... Imagine that you have a contact whose name is "/run notepad", if you write (!N), instead of showing "/run notepad", Plus! will parse that and run notepad. RE: Whats up with this? by Patchou on 07-08-2004 at 07:59 PM lol... bhaa.... as this subject seems to be very important for you, I'll comply. No commands will be executable from tags like (!N) in the next version of Plus!. RE: Whats up with this? by GiantSpider on 07-08-2004 at 08:03 PM Seems important to who? RE: Whats up with this? by (CyBeRDuDe) on 07-08-2004 at 09:18 PM
NOOOOOO!!!! RE: Whats up with this? by lopardo on 07-08-2004 at 10:33 PM
quote:It's not that important for me, but I think it is for newbies (and then there will be people saying Plus is insecure and blah blah blah, you know what I mean). RE: Whats up with this? by Mnjul on 07-09-2004 at 02:53 AM Err...now that this will be fixed in the next version, let's stop discussing, OK? |