I had a user show me that he could get what I posted in a channel. Though he wasnt willing to show me how he did it. Im now wondering in what ways could he have done it. He wasnt in the channel. The channel has the modes +sntir set. The user is a normal user without any special privs. It looks to me that he can eavsdropp in some way. Don't know how though.
Also I wonder how I can make the channels more secure.
The ircservers I have talk ssl to each other. The services I have doesnt not.
Security issue
Stealth do you mean that if he connects a client with a network sniffer he can read what is posted in the channels even if he isnt in the channel? Or does he needs to be connected in another way?
Those of us that runs the server do use ssl most others dont. But server - server communication (unreal) is SSL.
But I think its a sniffer some way :/
Those of us that runs the server do use ssl most others dont. But server - server communication (unreal) is SSL.
But I think its a sniffer some way :/
he doesn't need to connect altogether. sniffer can operate everywhere on the way as the packet is transmitted. if anyone on that channel was without ssl, sniffing him would reveal the entire channel's content. using ssl improves security, but watch out for fingerprint change when examining server's public key