Irssi ident bug

"Intel Nop" <[email protected]>
Newsgroups gmane.comp.security.invisiblenet.iip.devel,gmane.spam.detected
Message-ID <[email protected]>
i honestly didn't know that, thank you.
----- Original Message ----- 
From: "Jasper Jongmans" <[email protected]>
To: <[email protected]>
Sent: Saturday, December 14, 2002 5:16 AM
Subject: [iip-dev] Irssi ident bug


> On Fri, Dec 13, 2002 at 04:50:01PM -0800, 0x90 wrote:
> > - ---------------------------------------------------------
> > 
> > InvisibleNet Security Advisory ISA 2-1 [email protected]
> > 
> > http://www.invisiblenet.com
> > 
> > December 13th, 2002 - report issued by 0x90
> > 
> > - ---------------------------------------------------------
> > 
> > Subject: Irssi IRC Client (www.irssi.org) ident bug allowing users to
> > infiltrate/hijack users private conversations.
> > 
> > Vulnerability: Irssi Client doesn't distinguish nicknames in private
> > messages if ident info is the same. 
> > 
> > Problem-Type: remote but on same lan or same hostname.
> > 
> > OS Specific: *nix irssi users
> > 
> > Problem Description:
> > [Explanation of the securiy implications of the
> > query_track_nick_changes feature]
> > 
> > Vulnerable Versions:
> > 
> > 0.8.6 and any previous versions.
> > 
> > Solution:
> > 
> > Solution is being able to check the nick as well as ident info to
> > properly distinguish users for private messages, or rough cut, if a
> > private message is from a new nick, spawn a separate window. 
> > 
> > Patch:
> > 
> > A patch is not available at this time, for iip users specifically, it
> > is advised to discontinue use of irssi on IIP till a patch has been
> > released.
> > Note: InvisibleNet is working on a temporary patch until there is one
> > officially released from irssi.org.
> > 
> > Disclaimer:
> > 
> > 
> > InvisibleNet is not responsible for the misuse of any of the
> > information we provide on this website and/or through our security
> > advisories. 
> > Our advisories are a service to our customers intended to promote
> > secure
> > installation and use of InvisibleNet products.
> 
> /set query_track_nick_changes OFF
> 
> I would call this a feature, not a security bug. Of course, people using
> this feature should be aware of the security implications that go along
> with it, but that can be said about almost all features.
> 
> Why do I think this report is just a publicity stunt?
> 
> -- 
> Your ever whining watchdog,
> Jasper Jongmans                                   [email protected]
> Website                      http://aprogas.student.utwente.nl/~aprogas/
> PGP key                ftp://aprogas.student.utwente.nl/keys/pgp-dsa-elg
> PGP fingerprint       6E36 58CF 2CD7 86BC 7F6C  6128 E2AA FA44 CD25 1FFD
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.