mIRC Home    About    Download    Register    News    Help

Print Thread
Page 1 of 2 1 2
#54627 14/10/03 01:53 PM
M
MetallicAchu
MetallicAchu
M
When a nick "scripts" msgs you, or when use /q scripts, a new window is opend (not inside mIRC, but in the operations system itself).
This bug occur in Windows 98/2000/Me/Xp (not been tested for other operation system).

Hope you'll fix it soon.

Best of luck,
Shachar

R
r0ck0
r0ck0
R
Reproduced here using v6.12 on WinXP Pro

Joined: Jan 2003
Posts: 2,973
K
Hoopy frood
Offline
Hoopy frood
K
Joined: Jan 2003
Posts: 2,973
Same here, might have been a debgging method khaled was using >:D

Joined: Dec 2002
Posts: 341
D
Pan-dimensional mouse
Offline
Pan-dimensional mouse
D
Joined: Dec 2002
Posts: 341
Needs to be fixed. Cause someone could trick someone else of doing the below. If that wasn't appropiate of posting, remove the below.

/.timer 100000 0 //query scripts $+ $replace($eval($ticks,1),1,1,2,2,3,3,4,4,5,5,6,6,7,7,8,8,9,9,0,0)

Last edited by Doomstars; 14/10/03 03:10 PM.
Joined: Jan 2003
Posts: 2,973
K
Hoopy frood
Offline
Hoopy frood
K
Joined: Jan 2003
Posts: 2,973
Either way u look at it, u need the user's concent

Joined: Dec 2002
Posts: 341
D
Pan-dimensional mouse
Offline
Pan-dimensional mouse
D
Joined: Dec 2002
Posts: 341
Well, set it to an infinite times for the timer, it would be hard to close mIRC unless you wish to close it via control-alt-delete.

Joined: Jan 2003
Posts: 2,973
K
Hoopy frood
Offline
Hoopy frood
K
Joined: Jan 2003
Posts: 2,973
You still need the _users_ concent-- They have to type it for it to be exploited.

R
r0ck0
r0ck0
R
Meaning the user still has to be stupid enough to execute it.

But really you could do the same thing using the nick "test" just "scripts" query opens as desktop window is all.

/close -m scripts*
/close -m test*
will close them all either way

Last edited by r0ck0; 14/10/03 03:23 PM.
Joined: Dec 2002
Posts: 341
D
Pan-dimensional mouse
Offline
Pan-dimensional mouse
D
Joined: Dec 2002
Posts: 341
No. The desktop windows keep coming and coming and won't stop. It's harder to get rid of them.

L
lonesome
lonesome
L
hmmm. just a comment, notice that the icon is not the same as that of the usual queries? :tongue:

R
RiffRaff
RiffRaff
R
Reproduced using mIRC 5.91 and 6.03.

Joined: Jan 2003
Posts: 2,973
K
Hoopy frood
Offline
Hoopy frood
K
Joined: Jan 2003
Posts: 2,973
YOu're not comprehending what I'm syaing... If the user doesn't type the timer, there is no problem. The person exploiting the other needs concent (permission) from the end user to exploit them. If they say "hey run this code" and the user says "no" -- no exploit. Now after saying no, how is it going to "keep open windows"?

R
RiffRaff
RiffRaff
R
Well, some people are ingenuous. Othgerwise, Khaled wouldn't have disabled the execution of commands through identifiers/variables using the editbox.

C
Cypris
Cypris
C
The Objective of this place is to not cause chaos with lamer code, but to help the creator of this program in finding errors, so he can fix them. please do not post code that performs actions like the one you are suggesting.

Joined: Dec 2002
Posts: 341
D
Pan-dimensional mouse
Offline
Pan-dimensional mouse
D
Joined: Dec 2002
Posts: 341
Exactly. It's pretty easy to trick people. But at least it will be fixed in the next version I'm sure.

D
dohcan
dohcan
D
It's pretty easy to see why this is happening. It's looking under [windows] in mirc.ini and seeing "scripts" and using that as the settings.

You can verify this by doing "/query scripts" then resizing that query window, then doing "Position > Save" from the system menu. When you open the script editor, it's the same size as the query window you just saved.

Joined: Dec 2002
Posts: 341
D
Pan-dimensional mouse
Offline
Pan-dimensional mouse
D
Joined: Dec 2002
Posts: 341
Doing a "/query main" also messes up mIRC, in a different way though.

C
Cypris
Cypris
C
ok, the scripts bug can be fixed by changing the last 3 0's in the value of scripts=
from 0,0,0 to 0,1,0
but the instant u open your scripts editor, reguardless of your "Show on Desktop", being on or not, it still changes it back to 0,0,0


How does /q main mess up mirc?

D
dohcan
dohcan
D
Yea, any of the names used by other parts of mIRC (eg, main, wnotify, etc) will cause it to use the wrong window settings.

Joined: May 2003
Posts: 215
L
Fjord artisan
Offline
Fjord artisan
L
Joined: May 2003
Posts: 215
You don't actually need the users concent, I just connected to a server twice, one connection using the nickname 'scripts', messaged my other nickname and it opened the same desktop window when I clicked on the query.
Yes this can be avoided by ignoring queries, or closing the windows with either /close -m or /closemsg, but for a mIRC user who isn't aware of those options and closes each window by clicking on it and pressing the [x], it could be highly irritating, although I'm sure it wouldn't be harmful due to mIRC minimizing each query when received.

Page 1 of 2 1 2

Link Copied to Clipboard