Skip to content
MSN

DCC SEND in msn chat

A TG007 community discussion started by randall_xl.

Discussion 16 posts
Page 1 of 1
Open
Topic #6699 · 16 published posts · 4,505 views

lately myself and others have been being attacked by a chatter in msn chat. they will enter the room, type "DCC SEND 123456781234000" and it causes me to moof (myself only, doesnt moof anyone else).

 

How are they doing this and how can I prevent it from happening?

 

thanks in advance

Try this /ignore -d *!*@*

Custom Computer

AMD Athlon 64 x2 Dual Core 5200+

Asus M2N-SLI MOB

2GB DDR2 @ 800mhz

160GB Hard Drive

NVidia GeForce 8400GS 256

I forgot to mention, this happens when Im using the normal msn chat client, not when using a script

 

thanks again

i saww that in my room today but it did nothing and the guy left. i added that DCC SEND stuff to my word base kicks too.

 

Everywhere you go, there you are

it has nothing to do with the actual dcc send funtion but rather thats the "trigger" to start a local time flood. if u flood a chatter with local time they will moof

If your whispers are off youo should be fine and also depends on your connection speed. Dial Ups are known to DC quicker and if you have a stable connection DCC shouldnt affect you >>>>.raw PRIVMSG $1 $+(:,$chr(1),DCC) send<<<< thats all it is wont add the rest of it :pizza:

I've heard that this exploit affects NetGear and LinkSys routers, as well as older versions of Norton's Firewall. Are you using one of these products?

 

Google "IRC DCC SEND exploit" for more info.

Lol its probobly just people flooding you with time checks as someone said, anyone can be dc'ed pretty much on webchat apart from hosts but its possible to dc them aswell, if its that theres nothing you can do apart from tell a host about them.

Firstly, thank you all for your assistance.

 

It appears that certain Linksys (and possibly Netgear) routers will reset an IRC connection when a malformed DCC request is received. In fact, it doesn't even have to be a proper DCC request, the flaw can be triggered simply by sending the following string in either a channel, private message, ctcp, notice, etc.. The router will drop the connection. such that it is received by the user in some way. The string is as follows:

 

DCC SEND anylongrandomstringhere

 

It is most commonly being seen as "DCC SEND 1234567812340000" but that appears to be unneccessary. The string does need to be 15+ chars in length.

 

Further, it appears the routers that are vulnerable to this are running vxworks as their embedded OS. Older linux Linksys routers appear to be immune.

 

Linksys has a fix for this in their lates firmware release for the WRT54G ( v1.00.9)

 

You can also connect to a non-standard port and the masquerading code won't recognize it as an IRC connection

zomg localtime floods, such an old noob thing to do...

Risk® has joined the conversation.

Risk® : DCC SEND 12345678912345 00 00

DustyRoad27 has left the conversation.

erock1961 has left the conversation.

CulturalSnipe has left the conversation.

Host «TØTØ ßØT» kicked Risk® out of the chat room: OH CUT THAT SH** OUT (Access ban set for 3 hours)

 

 

it is sad to see these noobs still doing this. i have added his gatekeeper to my global ban list. sad that people get there rocks off doing this, funny thing, he only moofed 3 people out of 86 chatting. i have gaurd dog set to kick anyone who uses the word combo "DCC Send"

Edited Jul 20, 2006 1:37 AM by floydfan786

Everywhere you go, there you are

Wow, I must be out of sync with MSN.

I never even knew there were DCC exploits in MSN. o.o;

Comptia A+, MCP 2.0, MCTS x2

That is a old noob thing :taz: Noobs Suck :taz: but you could of explained it with out all the numbers behind it id hate for a noob to read the forum then go around trying it out. But ya more than likely it is your router :pizza:

 

get mirc 6.20 and you wont have that problem lol

My code does NOT have bugs. It just develops random features.

mirc 6.12+ stops the dcc exploit.. and they most people dont use DCC to disconnect someone they just use time flood.. to my knoledge.

wasnt much of a mirc disconnect.. guess it effected routers or something, like the expolit norton had with startkeylogger