OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: BitchX /ignore bug
From: Thomas Dullien (thomasRELAYGROUP.COM)
Date: Wed Jul 05 2000 - 08:57:17 CDT


At 05:44 AM 7/5/2000 -0500, you wrote:

>If I read this correctly, this is not an attack perse, but a self
>annihilation is it not? and while a bug, not something one can use to
>take others ofline or server, please correct me if I read this wrong.

Erm...the user you invited will die. And yes, this can be remotely exploited
to run arbitrary code I guess, too... (depends on whether you can get
backslashes into channel names...)