
|

 |
mIRC crash bug Another bug has been found in the most popular IRC client there is, mIRC. This bug only affects Windows XP users with any Service Pack (1 or 2), and it also doesn't matter whether you're on the Professional or Home edition.
You can crash your own mIRC (not anyone elses) by typing /dns 66.xxx.xx.x. It would seem that this will occur with any IP in the range of 66.xxx.xx.1 - 66.xxx.xx.x1. This is the third bug that has been found that can crash mIRC easily since the release of mIRC 6.1. The first two to be discovered are exploits, meaning other people can crash your mIRC. One of the exploits was fixed in version 6.12, and the other exploit can be protected against easily thanks to the hard work of IRC users (see article below). However, there is yet to be a release of what we assume will be called version 6.13, to address this bug and the second exploit.
If you receive any message from users asking you to dns an IP address and it starts with 66 (66.xxx.xx.x) don't do it because it will cause your mIRC client to crash.
Note: the xxx.xx.x in the IP address are used to mask the actual IP range, for obvious reasons.
October 27th 11:22am, Submitted by DJay |
 |
New mIRC 6.12 Released A new version of mIRC (6.12) has been released 2 days after the release of 6.11 was found to have a dcc exploit. The new version of mIRC addresses this issue as well as the userhost issue found in other previous versions. It is recommended that everyone updates to the new version available at http://www.mirc.co.uk/get.html
|
 |
mIRC 6.* exploit found A new exploit for mirc versions 6.* and above has been found, and has the potential to crash your mIRC program.
All versions of mIRC 6.* and above are subjectable to this exploit, and this includes the new version 6.11. For now, the only known fix is to ignore all DCC requests entirely. with the following command:
/ignore -wd *
For more information/faq please visit HERE
October 14th 6:40am, Submitted by Blase |
 |
Stay safe! Keep alert! There has been a small increase in AustNet users infected by viruses caught when visiting spammed websites or by dcc accepting dangerous file names. Users are advised to keep a watchful eye on filenames being recieved. Also be aware of any suspicious websites that are given on IRC (They are meant to mislead you!). They can be made to look harmless, but can infect your computer with a nasty virus.
The best protection against these nasties is a watchful eye and updated anti-virus software. Don't allow yourself to become a casualty, update today! :)
October 11th 12:02am, Submitted by Blase |
 |
Microsoft DCOM RPC vulnerability Microsoft has released details of a new threat which is able to exploit the Microsoft DCOM RPC vulnerability. The details of this vulnerability have been described in Microsoft Security Bulletin MS03-026. (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp) "Backdoor.IRC.Cirebot is a threat which exploits the Microsoft DCOM RPC vulnerability to install a backdoor Trojan Horse on vulnerable systems. Backdoor.IRC.Cirebot consists of a Backdoor component, and a Hacktool component which installs the backdoor on systems which are vulnerable to the exploit." As reported by the Symantec Security Response Team.
Users running Microsoft � Windows � are advised to download and apply the patch, which is an effective means of eliminating the vulnerability.
The security patches are available via this LINK (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)
August 4th 11:19pm, Submitted by Blase |
 |
eggdrop 1.6.15 op status bug Eggdrop 1.6.15 will incorrectly report that some non-opped users in a channel are opped. This may pose a serious problem, depending on what tcl files are used. The bug does not exist in versions 1.6.13 and earlier. It is recommended that users of 1.6.15 revert to an earlier version.
June 15th 6:10pm, Submitted by Deoau |
 |
New Email Virus uses Microsoft Email Users should be warned about a new rapidly circullating virus that pretends to come from Microsoft. Be on the look out for emails that pretend to come from [email protected]. The message can come with a variety of subject�s lines such as:
- Your Password
- Re: Movie
- Cool screensaver
- Your details
- Re: My details
- Approved (Ref: 38556-263)
Embedded in each emails is a worm called "Palyh", an attachment ending in *.pi. Once the attachment is executed it will copy itself to the windows directory and begin sending itself to every e-mail address it finds on the computer.
If you receive an email similar to this one delete it as soon as possible, and as always, if you have any questions please don't hesitate to see the nice people in #AVA :)
May 21st 6:01pm, Submitted by Blas� |
 |
BitchX: Crash when channel modes change On May the 7th 2003, a bug report was received which found a problem with BitchX for all versions up to 1.0c20cvs. Certain channel mode changes would cause BitchX to crash.
Thankfully the problem was quickly solved within 24 hours, and all BitchX users are urged to update to the current CVS available here: ftp://ftp.bitchx.org/pub/BitchX/cvs-snapshot
May 11th 2:37pm, Submitted by Blas� |
 |
Update your bookmarks!!! In recent weeks #AVA (AUSTnet Virus Assistance) has been through a positive transition period, part of which included a new domain name, which was unveiled last month (http://avassist.dot.nu). There have also been relevant website updates and additional information, enough to familiarize you with procedures to follow when infected with a possible virus.
May 8th 7:57pm, Submitted by Blas� |
 |
Malicious script Users who have a script called "access.ini" have had their nicknames stolen after the script sends their password to its creator every time they identify. The script's channel has been closed down. Any users of the script are advised to remove it immediately (/unload -rs access.ini *and* /remove access.ini) and then change their password (/msg nickop set pass yournewpassword).
To check if you have this script, simply open your remotes holding alt and pressing R >> click "VIEW" and look for "access.ini"
|
 |
Internet Explorer/Outlook Express Patches Microsoft has released another cumulative patch for Internet Explorer and Outlook Express which fixes all known security problems in these two products up to the time of the release. As the majority of visitors to the AustNet website appear to use IE we have included the URLs for the patches.
Available for download:
For Internet Explorer
For Outlook Express
April 27th 7:43pm, Submitted by Karl |
 |
New Malicious mIRC Script Users of "VMagnum" script have had their channels and nicknames stolen after the script sends their password to its creator every time they identify. The script's channel #snooker has been closed down and the creator removed from the network. Any users of the script are advised to remove it immediately and then change their password (/msg nickop set pass yournewpassword).
|
 |
Nickname stealing impersonators AustNet users are again reminded to never give your password out, or "identify" to anyone other than [email protected]. Austnet services will never require you to "identify" to any other service.
The most recent impersonator/nickname thief commonly uses a nickname like CONFIGPWD and sends a message saying something similar to
Austnet services will be restructuring shortly. In order to keep you current IDENTIFY password, please /msg NEWPASS . We apologise for the inconvenience.
Unfortunately many AustNet users have been fooled by this and sent their nickname password to the user using the nickname NEWPASS, who then steals their nickname. AustNet is contacting this user's ISP (Iinet) about his actions, but is warning all users not to identify to any other "service" than [email protected].
|
 |
Users advised to beware mIRC exploit Hopefully, the majority of IRCer's are familiar with the dangers associated with accepting unknown files through DCC, especially with files containing a double-extension. (e.g: picture1023.jpg.bat)
A new mIRC bug has been found which hides the full extension of the file. The unsuspecting user will receive a DCC get window which receives the filename as "picture1023.jpg", and hence the user will not see the ".bat" part of the filename. Then when the user clicks open, the file would execute.
Advisable steps to take to avoid getting caught executing a possible virus is to view the file you downloaded through explorer. Alternatively type //run $getdir and press enter to view the file. As always be careful whom you accept files from, and do not accept files from people you're unfamiliar with or don't trust.
If you have any questions please direct them to #AVA :)
April 9th 11:56am, Submitted by Blase |
 |
Virus Alert An old worm (wkbot) has been re-released into the wild with currently a high payload. The majority of people receive this virus from kazaa/imesh/IRC. As a means to help others infected with the ident problem Austnet has ignored the idents of affected users. The things to look out for are your ident being set to LL????? (random numbers replace the question marks) or a file called cmd32.exe or system32.exe. If you or a friend has found this then might be a good idea to take a visit into #ava for some assistance. As yet there is no fixfile for this virus and the online scanners are struggling to remove it (although they do detect it)
This virus has many malicious functions, some of these include;
Opens two randomly selected TCP and UDP ports to connect to the hacker.
Listens for the commands from the hacker using its own IRC channel.
The commands allow the hacker to perform any of the following actions:
Upgrade the worm
Steal the system/network information and send it to the hacker
Download and execute files
Perform Denial of Service (DoS) attacks against the hacker's targets
Send the worm to other IRC users
More information on this virus can be obtained from #ava or from Symantec
|
 |
Buffer overflows in IRC-II based clients If you are using an IRC-II based client, then you should be aware of the latest reported security threat. A post on Security focus has listed few vulnerabilities, which could be exploited if a user connects to a malicious server. However, only users with the correct authority, such as server administrators can only make use of these bugs. Regular users are unable to exploit these bugs. In order to avoid being compromised users should avoid connecting to un-trusted servers and not IRC over insecure network links. Author of the post, Timo Sirainen said:
"After seeing the BitchX "DoS" problem mentioned the n'th time already, I decided to finally audit ircII based clients to show some worse problems they have. I had been pretty sure for years that malicious servers can exploit them in multiple ways, and I think many others have known it as well. EPIC and ircII authors have been working to fix these, but looks like their job isn't yet finished." Timo Sirainen's entire article can be seen HERE.
March 22nd 11:54am, Submitted by blase |
 |
Microsoft issues security alert A new security alert highlights a critical security bug in all Windows� products. This exploit could be used to run malicious scripts. Affected products are Windows 98, 98SE, ME, NT 4, NT 4 Server edition, 2000 and XP. All users are urged to download the latest security updates available HERE Read the alert HERE.
The attacker would first have to send you an e-mail message or entice you into visiting a malicious Web site. AustNet would like to take this opportunity to remind all users to not go to any links which are sent to you on entry or parting of channels, or in conversations with strangers. Prevention can often be better than the cure.
March 20th 11:52am, Submitted by lolly |
 |
|
| |