View Issue Details

IDProjectCategoryView StatusLast Update
0002580unrealircdpublic2005-07-02 12:15
Reportervonitsanet Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionno change required 
Product Version3.2.4 
Summary0002580: The crazy szline form accepted by unreal
Description-xxxxxxx.xxxx.x- *** Global Z:line added for *@* on Fri Jul 1 13:04:33 2005 GMT (from services.x.x to expire at Fri Jul 1 13:05:03 2005 GMT: .)

This z:line was sent from a services server and was accepted by unrealircd.
I thing Unreal should not accept this z:line even if was sent from u:line (even if was sent from the god..)

(i have not tested if this can happened to SVSNLINE G:Lines and sqline too)
Steps To ReproduceJust send from a services server an gzline command and it will be accepted from all servers..
3rd party modulesNONE

Activities

vonitsanet

2005-07-01 10:08

reporter   ~0010150

Last edited: 2005-07-01 10:09

I have tested it now for svsnline and sqline.

Unreal accepts SVSNLINES for the mask *:
n * Invalid real name: test

and it not accept SQLINES for *

Stealth

2005-07-01 19:01

reporter   ~0010152

Last edited: 2005-07-01 19:02

Services should be able to do whatever they want, thats how it was made to be... The reason it would not accept SQLINE *, is because that is an impossible SQLINE which would need to disconnect everyone and not allow anyone back on to undo it.

EDIT: I don't think Unreal should accept SVSNLINE *, for the same reasons as SQLINE.

w00t

2005-07-01 22:46

reporter   ~0010153

I think the main issue here is that people should know what they're doing. The only people who should be adding this kind of functionality into services are the services coders themselves. read: if you're using RAW to set this kind of thing, you're a moron regardless.

Adding checks on this kind of thing is only going to slow things up just that little bit more - is it worth it for the idiots out there who go around mucking about with this kind of thing?

codemastr

2005-07-02 12:15

reporter   ~0010155

It is working as designed. Services have full access. If you think it's a problem, then don't give services root access to people you don't trust.

Issue History

Date Modified Username Field Change
2005-07-01 09:50 vonitsanet New Issue
2005-07-01 09:50 vonitsanet 3rd party modules => NONE
2005-07-01 10:08 vonitsanet Note Added: 0010150
2005-07-01 10:09 vonitsanet Note Edited: 0010150
2005-07-01 19:01 Stealth Note Added: 0010152
2005-07-01 19:02 Stealth Note Edited: 0010152
2005-07-01 22:46 w00t Note Added: 0010153
2005-07-02 12:15 codemastr Status new => closed
2005-07-02 12:15 codemastr Note Added: 0010155
2005-07-02 12:15 codemastr Resolution open => no change required