mIRC DCC Nick Disclosure Vulnerability
BID:4247
Info
mIRC DCC Nick Disclosure Vulnerability
| Bugtraq ID: | 4247 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2002 12:00AM |
| Updated: | Mar 07 2002 12:00AM |
| Credit: | Reported by James Evans <[email protected]>. |
| Vulnerable: |
Khaled Mardam-Bey mIRC 6.0 1 Khaled Mardam-Bey mIRC 6.0 |
| Not Vulnerable: | |
Discussion
mIRC DCC Nick Disclosure Vulnerability
mIRC is a popular IRC client for Microsoft Windows. DCC is a protocol used to enhance the functionality of IRC. Most commonly it is used to transfer files between clients, although it can also be used for direct conversations.
A vulnerability has been reported in the mIRC implementation of the DCC protocol. Reportably, when a DCC connection initiated, the command '100 testing' will cause the mIRC server to respond with the user's current nick. Exploitation of this vulnerability may aid an attacker in further intelligent attacks, or help an attempt at social engineering.
mIRC is a popular IRC client for Microsoft Windows. DCC is a protocol used to enhance the functionality of IRC. Most commonly it is used to transfer files between clients, although it can also be used for direct conversations.
A vulnerability has been reported in the mIRC implementation of the DCC protocol. Reportably, when a DCC connection initiated, the command '100 testing' will cause the mIRC server to respond with the user's current nick. Exploitation of this vulnerability may aid an attacker in further intelligent attacks, or help an attempt at social engineering.
Exploit / POC
mIRC DCC Nick Disclosure Vulnerability
No exploit is required.
No exploit is required.