View Issue Details

IDProjectCategoryView StatusLast Update
0001215unrealircdpublic2003-12-29 20:21
Reporterfox Assigned Toluke  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionopen 
Summary0001215: [Stable] failed /oper logging
Descriptionircd doesn't log FAILEOPER to opers.log because it returns from m_oper function immediately as it doesn't find matching line.
from s_user.c (m_oper function)

        if (!(aconf =
            find_conf_exact(name, sptr->username, sptr->sockhost, CONF_OPS))
            && !(aconf =
            find_conf_exact(name, sptr->username, inetntoa((char *)&cptr->ip),
            CONF_OPS)))
        {
                sendto_one(sptr, err_str(ERR_NOOPERHOST), me.name, parv[0]);
                sendto_realops("Failed OPER attempt by %s (%s@%s)",
                    parv[0], sptr->user->username, sptr->sockhost);
                sptr->since += 7;
                return 0;
        }

So the above code doesn't give ircd an opportunity to log the attempt.
3rd party modules

Activities

fox

2003-08-28 15:46

reporter   ~0003530

found that FAILOPER is logged only if the username exists in ircd.conf.
otherwise user is notified by "No O-Lines for your host".

So we aren't able to monitor brute force attacks unless we're online.

Issue History

Date Modified Username Field Change
2003-08-28 15:35 fox New Issue
2003-08-28 15:46 fox Note Added: 0003530
2003-09-05 21:24 syzop Assigned To => luke
2003-09-05 21:24 syzop Status new => assigned
2003-09-05 21:24 syzop ETA none => > 1 month
2003-09-05 21:24 syzop Summary ircd doesn't log FAILOPER to opers.log => [Stable] failed /oper logging
2003-12-29 20:21 syzop Status assigned => closed