Irssi ident bug

Jasper Jongmans <[email protected]>
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Message-ID <[email protected]>
On Fri, Dec 13, 2002 at 04:50:01PM -0800, 0x90 wrote:
> - ---------------------------------------------------------
> 
> InvisibleNet Security Advisory ISA 2-1 [email protected]
> 
> http://www.invisiblenet.com
> 
> December 13th, 2002 - report issued by 0x90
> 
> - ---------------------------------------------------------
> 
> Subject: Irssi IRC Client (www.irssi.org) ident bug allowing users to
> infiltrate/hijack users private conversations.
> 
> Vulnerability: Irssi Client doesn't distinguish nicknames in private
> messages if ident info is the same. 
> 
> Problem-Type: remote but on same lan or same hostname.
> 
> OS Specific: *nix irssi users
> 
> Problem Description:
> [Explanation of the securiy implications of the
> query_track_nick_changes feature]
> 
> Vulnerable Versions:
> 
> 0.8.6 and any previous versions.
> 
> Solution:
> 
> Solution is being able to check the nick as well as ident info to
> properly distinguish users for private messages, or rough cut, if a
> private message is from a new nick, spawn a separate window. 
> 
> Patch:
> 
> A patch is not available at this time, for iip users specifically, it
> is advised to discontinue use of irssi on IIP till a patch has been
> released.
> Note: InvisibleNet is working on a temporary patch until there is one
> officially released from irssi.org.
> 
> Disclaimer:
> 
> 
> InvisibleNet is not responsible for the misuse of any of the
> information we provide on this website and/or through our security
> advisories. 
> Our advisories are a service to our customers intended to promote
> secure
> installation and use of InvisibleNet products.

/set query_track_nick_changes OFF

I would call this a feature, not a security bug. Of course, people using
this feature should be aware of the security implications that go along
with it, but that can be said about almost all features.

Why do I think this report is just a publicity stunt?

-- 
Your ever whining watchdog,
Jasper Jongmans                                   [email protected]
Website                      http://aprogas.student.utwente.nl/~aprogas/
PGP key                ftp://aprogas.student.utwente.nl/keys/pgp-dsa-elg
PGP fingerprint       6E36 58CF 2CD7 86BC 7F6C  6128 E2AA FA44 CD25 1FFD
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.