View Issue Details

IDProjectCategoryView StatusLast Update
0001994unrealircdpublic2004-07-27 16:41
Reportertigra Assigned To 
PrioritynormalSeveritytrivialReproducibilityalways
Status closedResolutionopen 
Product Version3.2.1 
Summary0001994: "k-line" check and "Q-lined nick" check order
DescriptionQ-line nick check goes before k-line check, therefore we can produce server-notice flood on Q-line nick even address are k-lined(g-lined,z-lined?).

example:
[21:50:05] -irc.*.ru- *** K:Line added for *@cab-98-35-10-10.nv.city on Tue Jul 27 15:50:04 2004 GMT (from Tigra!tigra@* to expire at Tue Jul 27 15:51:04 2004 GMT: ( Casper ) check, 1 minute)
[21:50:05] * Quits: Casper ([email protected]) (User is banned (( Casper ) check, 1 minute))
[21:50:27] -irc.*.ru- Q:lined nick FUCK from <unregistered> on irc.*.ru
[21:50:27] -irc.*.ru- Forbidding Q-lined nick FUCK from [10.10.35.98].
...............snotice flood...............
[21:50:44] -irc.*.ru- Tigra!tigra@* removed K:Line *@cab-98-35-10-10.nv.city (set at Tue Jul 27 15:50:04 2004 - reason: ( Casper ) check, 1 minute)

3rd party modules

Activities

syzop

2004-07-27 14:12

administrator   ~0007255

Correct, that's how things work.
To disconnect a user immediately if banned use (G)ZLINE (which takes place immediately upon incoming connection, before ident/dns/user/nick/etc)

tigra

2004-07-27 14:36

reporter   ~0007256

Correct, that's how things work.
To disconnect a user immediately if banned use (G)ZLINE (which takes place immediately upon incoming connection, before ident/dns/user/nick/etc)

---
what a difference - k-line or g-line (except local/global ban)? If you are banned, then you are banned.

syzop

2004-07-27 14:42

administrator   ~0007257

Uhh, I just explained.
a (G)ZLINE takes place immediately upon incoming connection.
a KLINE/GLINE takes place after DNS has been resolved (or attempted to), ident has been looked up (if enabled), and USER+NICK has been received.

tigra

2004-07-27 15:04

reporter   ~0007258

Last edited: 2004-07-27 15:20

ok, thnx

---
a KLINE/GLINE takes place after DNS has been resolved (or attempted to), ident has been looked up (if enabled), and USER+NICK has been received.

---
but why not place [KG]LINE check after DNS/ident lookup and before USER+NICK has been received?

is it RFC restriction?

edited on: 2004-07-27 15:20

codemastr

2004-07-27 15:21

reporter   ~0007259

but why not place [KG]LINE check after DNS/ident lookup and before USER+NICK has been received?

is it RFC restriction?
--

Well, if ident fails, we use the username specified in USER for matching. If USER has not yet been received, we have nothing to match.

tigra

2004-07-27 15:49

reporter   ~0007260

Last edited: 2004-07-27 15:50

does ZLINE/GZLINE do a DNS lookup? If I put a hostmask in this list, does line affect on match by DNS name?

edited on: 2004-07-27 15:50

codemastr

2004-07-27 15:52

reporter   ~0007261

Zlines are IP only, so no.

tigra

2004-07-27 15:59

reporter   ~0007262

why not add hostmask support to zline? w/o ident check, only on host or ip masks?
It will by more flexible, imho

codemastr

2004-07-27 16:00

reporter   ~0007263

Because then you have to wait for DNS.

syzop

2004-07-27 16:02

administrator   ~0007264

Because a [g]zlines are so powerful because they get enforced _immediately_ (=nearly no resources). Adding DNS support would mean disconnects could be delayed several seconds which is exactly what [g]zlines are ment to prevent.

tigra

2004-07-27 16:13

reporter   ~0007265

kline/gline hostmask + possible flood, zline/gzline iponly

dilemma :)

syzop

2004-07-27 16:16

administrator   ~0007266

Or just don't set the qlines snomask (mode nick +s -q) :P.
(which is what I always do since I'm not interrested in them at all and only find them annoying).

tigra

2004-07-27 16:28

reporter   ~0007267

Last edited: 2004-07-27 16:33

Or just don't set the qlines snomask (mode nick +s -q) :P.
---
or add new line, hline

Is delay on DNS query so significal? what about benchmarks? mb it is not so bad? ;)

edited on: 2004-07-27 16:33

Issue History

Date Modified Username Field Change
2004-07-27 12:25 tigra New Issue
2004-07-27 14:12 syzop Note Added: 0007255
2004-07-27 14:36 tigra Note Added: 0007256
2004-07-27 14:42 syzop Note Added: 0007257
2004-07-27 15:04 tigra Note Added: 0007258
2004-07-27 15:20 tigra Note Edited: 0007258
2004-07-27 15:21 codemastr Note Added: 0007259
2004-07-27 15:49 tigra Note Added: 0007260
2004-07-27 15:50 tigra Note Edited: 0007260
2004-07-27 15:52 codemastr Note Added: 0007261
2004-07-27 15:59 tigra Note Added: 0007262
2004-07-27 16:00 codemastr Note Added: 0007263
2004-07-27 16:02 syzop Note Added: 0007264
2004-07-27 16:13 tigra Note Added: 0007265
2004-07-27 16:16 syzop Note Added: 0007266
2004-07-27 16:28 tigra Note Added: 0007267
2004-07-27 16:33 tigra Note Edited: 0007267
2004-07-27 16:41 syzop Status new => closed