#151 closed defect (fixed)

Root talks

Reported by: Quis Owned by:
Priority: critical Milestone:
Component: BitlBee Version: 1.0.2
Keywords: injection Cc:
IRC client+version: Client-independent Operating System: FreeBSD
OS version/distro: FreeBSD 6.0-RELEASE-p4 FreeBSD 6.0-RELEASE-p4 #2: Fri Jan 27


My root talks to me :|

13:47 <@root> Lol , :) test'
15:38 <@root> lol ik wil eindelijk een enter'
15:45 <@root> lol'

These things he said Note the ' at the ending of al his sayings It might be that there is some sort of an 'SQL-injection' in bitlbee I don`t know whether this comes from MSN or bitlbee I think it is bitlbee

This seems like a security hole to me...

Attachments (0)

Change History (7)

comment:1 Changed at 2006-05-12T22:24:23Z by wilmer

Hmmm... If this ever happens again, please send me a log of the complete traffic between BitlBee and your IRC client around that moment.

comment:2 Changed at 2006-05-13T14:14:25Z by Quis

It happened again after I set AuthMode to Closed

01:15 <@root> MSN - Logged in
01:15 -!- XXX [***] has joined &bitlbee
01:15 -!- XXXX [***] has joined &bitlbee
01:15 <@root> .
01:15 <@root> Enter in your name'
01:51 <@root> .
01:51 <@root> Rabbit :0'
01:51 <@root> .
01:51 <@root> Rabbit :)'
01:51 <@root> .
01:51 <@root> ^^'
01:52 <@root> .
02:14 <@root> .
02:16 -!- XXX [***] has quit [Leaving...]
02:17 <@root> .
02:18 <@root> .
02:18 <@root>  Ben GEK!!!'

Do you want the raw irc-protocol data? or just a log from &bitlbee?

From now on I am logging both...

comment:3 Changed at 2006-05-13T14:16:37Z by wilmer

Hmmm, interesting conversations you're having. :-P

Yeah, raw IRC-protocol data please. This is pretty strange.

comment:4 Changed at 2006-05-13T14:51:31Z by Quis

Not that interesting :P It is only a one-way communication (I hope!) so don`t blame me :P

I`ve send the rawlog by email

comment:5 Changed at 2006-05-13T17:12:09Z by wilmer

Resolution: worksforme
Status: newclosed

Okay, we tracked it down now. Turns out one of Quis' buddies found out how to put newlines in his "friendly name". Since Quis uses the "display name changes" option and the bitlbee_name_change script, that first line gets swallowed by the script, and the other lines then look a bit strange. :-)

BitlBee should maybe strip those newlines...

comment:6 Changed at 2007-11-21T03:07:35Z by anonymous

Resolution: worksforme
Status: closedreopened

comment:7 Changed at 2007-11-21T08:42:47Z by wilmer

Resolution: fixed
Status: reopenedclosed

DIE, fucking spammer, DIE!

(Actual spam removed.)

Modify Ticket

as closed The ticket will remain with no owner.
The resolution will be deleted. Next status will be 'reopened'.

Add Comment

E-mail address and name can be saved in the Preferences.

Note: See TracTickets for help on using tickets.