Re: the right ircd for Blitzed

Andy Smith <[email protected]>
Newsgroups gmane.network.irc.blitzed.general
Message-ID <[email protected]>
On Sat, Jul 17, 2004 at 07:49:24PM -0400, Michael Reynolds wrote:
> While I've not really been part of the blitzed community, I have been an 
> avid reader of the lists, and feel I should give some input here.

You're welcome..

> Andy Smith wrote:
> >On Sat, Jul 17, 2004 at 10:52:43PM +0200, Philipp Kern wrote:
> <snip>
> >>Ok, but still there's no need for many IPv6 servers. I use it by myself,
> >>but there are rarely more than eight people online on soylent-green.
> >
> >
> >That's true although regardless of how many users there is, you do
> >need multiple servers for redundancy.  If IPv6 were something we
> >wanted to promote then we should probably have one server at each
> >place we can have one.
> >
> >I know that you want to run an IPv6 server, and I'm sympathetic to
> >this desire, but not when the code is so bad that it could risk
> >significant problems for the rest of the network.
> 
> The reason there is no IPv6 support in bahamut is that virtually no ISPs 
> support it.  After HE.net started blocking IRC on their IPv6 network, 
> and after the Foonet raid, IPv6 usage on IRC dropped to almost the point 
> that supporting it is a lost cause.

I must disagree that this is the only reason.  I know HE.net blocks
IRC, but HE.net is an American IPv6 tunnel provider.  We already
know that North America doesn't really care about IPv6, but there is
a lot to IPv6 outside of North America.

I think that bahamut does not contain IPv6 because it makes the
coders' lives more difficult.  The Azzurra patch which I've seen
(and we use on that one server) shows this up: the presentation
format of IPv4 addresses is inconsistent, klines and akills have
problems matching and even being set on IPv6 IPs, basically the
handling of IPs all over the ircd has to be changed so I can see why
they would rather not bother.

> >I'm told that RC4 is no weaker than the protocols SSL uses[1].  I've
> >not enough knowledge of cryptology to tell, and to be honest for the
> >sake of IRC I think even compressed links are too much trouble for
> >the average attacker.  The issue over SSL vs RC4 is for me one of
> >standardisation.  SSL is more standard than ad hoc RC4, so the could
> >would be cleaner.
> 
> Isn't RC4 one of the encryption protocols used by SSL?

Yes.

> Anyway, SSL is more standard, as it's on pretty much every machine
> with sshd already, cutting the need for custom encryption systems.

Yes.

> DNS spam is an ideal solution, just like giving a bum on the street a 
> few bucks.  Doesn't do squat for the cause. (Don't confuse bum with 
> homeless).  Blocking users because of this ideal does absolutely nothing 
> but send the users to other networks.

We don't currently turn away users for "DNS SPAM", we just laugh at
them.

> Many networks who implemented masks to protect users have come crashing 
> down due to warez channel wars.  I've seen it happen too many times for 
> it to be just coincidence.  When you take away their ability to packet 
> each other, who do you think they will go after next?

That is cetainly a possiblity, although many networks seem to have
hostmasking without problems, I am not sure they also ban file
trading although I'm in favour of that too.

> Google results for unrealircd vulnerability: 9,450
> Google results for bahamut vulnerability: 1,000
> Compare this with the number of networks using the two IRCds, and it 
> makes a huge difference.

But Unreal is also used by a LOT more networks than bahamut is, and
bahamut's web site efforts are always laughable.  So I'm not
surprised that news of any given exploit in Unreal travels further
than bahamut.

However I do concede that Unreal undoubtedly has more exploits in it
due to it being a larger code base, and when a new one is found we
would be ripe for targeting.

> UnrealIRCd has this disease creeping into many a software: featuritis. 
> Many (in fact, most) of these features seem to be built with the intent 
> on abuse.  Umode I? Using SAJOIN to force people to join channels? 
> Spying on privmsgs?  +u (if that's auditorium mode) to block people from 
> seeing who's in a channel?  I've seen the latter used by virtually every 
> DDoS botnet writer to hide his bots in the open, so to speak.  Doesn't 
> speak to well for the IRCd.  (And yes, I know the creator can't do jack 
> about who uses the IRCd, but he could do jack to deter it.)

All of those "features" can be disabled.  umode +I isn't even in the
code anymore.

_______________________________________________
public mailing list
public-Hb7ITwsGSD4lroQnaJEqWdi2O/[email protected]
http://lists.blitzed.org/listinfo/public
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFA+cbtIJm2TL8VSQsRApVtAKCYi8LSZAISbAdnh5LWJfdWy6BJaQCfXie2
g/6JBnirznGAMhYy8iVoOsg=
=oJ7y
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.