Linked Eggdrop IRC Bot Unauthorized Proxy Vulnerability
BID:6813
Info
Linked Eggdrop IRC Bot Unauthorized Proxy Vulnerability
| Bugtraq ID: | 6813 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2003 12:00AM |
| Updated: | Feb 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: Paul Starzetz <[email protected]> |
| Vulnerable: |
Eggheads Eggdrop IRC bot 1.6.13 Eggheads Eggdrop IRC bot 1.6.12 Eggheads Eggdrop IRC bot 1.6.11 Eggheads Eggdrop IRC bot 1.6.10 |
| Not Vulnerable: | |
Discussion
Linked Eggdrop IRC Bot Unauthorized Proxy Vulnerability
It has been reported that Eggdrop IRC bot when linked to a botnet is vulnerable to an access validation error. This may in some cases, allow unauthorized users to use any linked instance of a bot on the botnet as a proxy server.
It has been reported that Eggdrop IRC bot when linked to a botnet is vulnerable to an access validation error. This may in some cases, allow unauthorized users to use any linked instance of a bot on the botnet as a proxy server.
Exploit / POC
Linked Eggdrop IRC Bot Unauthorized Proxy Vulnerability
This vulnerability may be exploited using an IRC client.
This vulnerability may be exploited using an IRC client.
References
Linked Eggdrop IRC Bot Unauthorized Proxy Vulnerability
References:
References:
- Eggdrop IRC bot Homepage (Eggheads)
- Eggdrop arbitrary connection vulnerability (Paul Starzetz
)