Irssi ident bug
"Intel Nop" <[email protected]>
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel,gmane.spam.detected |
|---|---|
| Message-ID | <[email protected]> |
it's more directed at IIP users, and that's why the advisory was written. It's not a public advisory, and is directed at IIP. Thank you for that solution, I was trying to figure out the problem at the code level, and you saved a lot of work. I'm glad you were able to assist with this problem. Thnx. 0x90 ----- Original Message ----- From: "Jasper Jongmans" <[email protected]> To: <[email protected]> Sent: Saturday, December 14, 2002 5:16 AM Subject: [iip-dev] Irssi ident bug > On Fri, Dec 13, 2002 at 04:50:01PM -0800, 0x90 wrote: > > - --------------------------------------------------------- > > > > InvisibleNet Security Advisory ISA 2-1 [email protected] > > > > http://www.invisiblenet.com > > > > December 13th, 2002 - report issued by 0x90 > > > > - --------------------------------------------------------- > > > > Subject: Irssi IRC Client (www.irssi.org) ident bug allowing users to > > infiltrate/hijack users private conversations. > > > > Vulnerability: Irssi Client doesn't distinguish nicknames in private > > messages if ident info is the same. > > > > Problem-Type: remote but on same lan or same hostname. > > > > OS Specific: *nix irssi users > > > > Problem Description: > > [Explanation of the securiy implications of the > > query_track_nick_changes feature] > > > > Vulnerable Versions: > > > > 0.8.6 and any previous versions. > > > > Solution: > > > > Solution is being able to check the nick as well as ident info to > > properly distinguish users for private messages, or rough cut, if a > > private message is from a new nick, spawn a separate window. > > > > Patch: > > > > A patch is not available at this time, for iip users specifically, it > > is advised to discontinue use of irssi on IIP till a patch has been > > released. > > Note: InvisibleNet is working on a temporary patch until there is one > > officially released from irssi.org. > > > > Disclaimer: > > > > > > InvisibleNet is not responsible for the misuse of any of the > > information we provide on this website and/or through our security > > advisories. > > Our advisories are a service to our customers intended to promote > > secure > > installation and use of InvisibleNet products. > > /set query_track_nick_changes OFF > > I would call this a feature, not a security bug. Of course, people using > this feature should be aware of the security implications that go along > with it, but that can be said about almost all features. > > Why do I think this report is just a publicity stunt? > > -- > Your ever whining watchdog, > Jasper Jongmans [email protected] > Website http://aprogas.student.utwente.nl/~aprogas/ > PGP key ftp://aprogas.student.utwente.nl/keys/pgp-dsa-elg > PGP fingerprint 6E36 58CF 2CD7 86BC 7F6C 6128 E2AA FA44 CD25 1FFD > >