SIRCD Server Operator Privilege Escalation Vulnerability
BID:9097
Info
SIRCD Server Operator Privilege Escalation Vulnerability
| Bugtraq ID: | 9097 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2003 12:00AM |
| Updated: | Nov 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Victor Jerlin <vigge vigge fulhack nu>. |
| Vulnerable: |
sircd sircd 0.5.3 sircd sircd 0.5.2 |
| Not Vulnerable: | |
Discussion
SIRCD Server Operator Privilege Escalation Vulnerability
sircd has been reported prone to a privilege escalation vulnerability. It has been reported that any user logged on to the sircd server, may set their usermode to +o, or operator mode.
An attacker may exploit this condition to hijack IRC channels or impersonate users, these privileges may aid the attacker in further attacks launched against the target server.
sircd has been reported prone to a privilege escalation vulnerability. It has been reported that any user logged on to the sircd server, may set their usermode to +o, or operator mode.
An attacker may exploit this condition to hijack IRC channels or impersonate users, these privileges may aid the attacker in further attacks launched against the target server.
Exploit / POC
SIRCD Server Operator Privilege Escalation Vulnerability
The following IRC directive may be used to elevate privileges:
MODE <nick> +o
The following IRC directive may be used to elevate privileges:
MODE <nick> +o
Solution / Fix
SIRCD Server Operator Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SIRCD Server Operator Privilege Escalation Vulnerability
References:
References:
- sircd (sircd)
- SIRCD: Anyone can set umode +o(oper). (Victor Jerlin
)