Security Threats - Through Admins and servers, links etc

These are old archives. They are kept for historic purposes only.
Post Reply
RhiN0
Posts: 4
Joined: Sun Nov 13, 2005 12:21 am

Security Threats - Through Admins and servers, links etc

Post by RhiN0 »

Alright i want ot make my own irc server, i got a temp one, but if i want to make a real one ill have to get it on a good computer and fast internet, i need to know if there are threats that links can produce (i.e thru editing of the .conf file to add their own admins. Now i really dont know the difference of Hub And Leaf - from what ive tried to put together, Hub is like the central server - then leafs connect to the central server, and players can be connected to the hub and the leaf - but im guessing Hub has more power?

basically i want to know the possible risks if i decide to host something i worked on somewhere else
w00t
Posts: 1136
Joined: Thu Mar 25, 2004 3:31 am
Location: Nowra, Australia

Post by w00t »

Not quite sure what you're meaning.. if you mean other servers- if they add their own o:lines (as they can) - they can do damage. This is why you get to know and trust someone (as an IRC admin, not as a person) before linking to them.

If you mean hosting your server externally, most people do that.
-ChatSpike IRC Network [http://www.chatspike.net]
-Denora Stats [http://denora.nomadirc.net]
-Omerta [http://www.barafranca.com]
RhiN0
Posts: 4
Joined: Sun Nov 13, 2005 12:21 am

Post by RhiN0 »

so all servers (both leaves and hubs) can produce the same secruity risks thru their ability to make o lines?
Solutech
Posts: 296
Joined: Thu Mar 18, 2004 11:38 pm

Post by Solutech »

yup anyone who can add olines can cause you grief . As W00t says make sure you trust whoever you give olines to .
Yawn. So there's yet another "if the user clicks the button, they're infected" exploit. Why is this news? We already know users are idiots.
Matridom
Posts: 296
Joined: Fri Jan 07, 2005 3:28 am

Post by Matridom »

I learned the hardway (when setting up my own server years ago) that there is a "quarantine" option for the link block, it disables IRCop's from that server from having the same right on your server. meaning, he can't kill someone on your server from his. However, it causes issues with services.

Otherwise i would agree with everyone, know and trust the people you deal with.
Never argue with an idiot. They will bring you down to their level, then beat you with experience.
aquanight
Official supporter
Posts: 862
Joined: Tue Mar 09, 2004 10:47 pm
Location: Boise, ID

Post by aquanight »

quarantine doesn't work :P
Matridom
Posts: 296
Joined: Fri Jan 07, 2005 3:28 am

Post by Matridom »

aquanight wrote:quarantine doesn't work :P
it did back in 3.1.12 beta :)
Never argue with an idiot. They will bring you down to their level, then beat you with experience.
w00t
Posts: 1136
Joined: Thu Mar 25, 2004 3:31 am
Location: Nowra, Australia

Post by w00t »

Actually, I looked at this the other day, and I'm not too sure why it wouldn't be working.. unless it's some bizarre conf voodoo. The MODE code checks for quarantine properly and reverses changes (or should) ok...
-ChatSpike IRC Network [http://www.chatspike.net]
-Denora Stats [http://denora.nomadirc.net]
-Omerta [http://www.barafranca.com]
Jason
Posts: 570
Joined: Mon Jun 14, 2004 5:09 pm

Post by Jason »

Is there some minor name difference in the checked variable?
Why the hell can't my signature be empty?
"Your message contains too few characters."
Post Reply