From cd01eeadcbf5e5e1c81244b69b5c9079a3b58675 Mon Sep 17 00:00:00 2001 From: Test_User Date: Mon, 6 May 2024 07:17:17 -0400 Subject: multi-haxserv priv escalation fixed --- client_network.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) (limited to 'client_network.c') diff --git a/client_network.c b/client_network.c index f333344..93ad1d9 100644 --- a/client_network.c +++ b/client_network.c @@ -156,10 +156,6 @@ int add_local_client(struct string uid, struct string nick_arg, struct string vh SEND(NULSTR(string_time)); SEND(STRING(" +k :")); SEND(realname); - SEND(STRING("\n:")); - SEND(uid); - SEND(STRING(" OPERTYPE ")); - SEND(opertype); SEND(STRING("\n")); if (fake_cert) { SEND(STRING(":1HC METADATA ")); @@ -168,6 +164,13 @@ int add_local_client(struct string uid, struct string nick_arg, struct string vh SEND(client_cert); SEND(STRING("\n")); } + if (!STRING_EQ(uid, STRING("1HC000000"))) { // Don't oper haxserv, because echo is unprivileged + SEND(STRING(":")); + SEND(uid); + SEND(STRING(" OPERTYPE ")); + SEND(opertype); + SEND(STRING("\n")); + } return 0; -- cgit v1.2.3