View Issue Details

IDProjectCategoryView StatusLast Update
0003490unrealircdpublic2007-08-03 01:45
ReporterCuttingEdgeAssigned Tostskeeps 
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionfixed 
Platformi386OSLinuxOS Version2.6.18
Product Version4.0-devel 
Target VersionFixed in Version4.0-devel 
Summary0003490: Hide +j and +f secondary variables from /LIST for regular users
DescriptionCurrently +j and +f secondary variables are displayed in /LIST for regular users. This should be fine for IRC operators though. I reckon this could pose as a security threat of sorts, as then people that abuse channels can adjust their method of attack to be within these thresholds. Currently the Unreal 3.2.* branch hides these variables too.
TagsNo tags attached.
3rd party modules

Relationships

child of 0003417 closed TODO list for Unreal4.0 

Activities

Shining Phoenix

2007-07-28 20:54

reporter   ~0014621

I reckon this could pose as a security threat of sorts, as then people that abuse channels can adjust their method of attack to be within these thresholds.
=====
Hmm...they could still join one bot, see the f param, and then get around it. I have seen bots stay just within f before ><

Stealth

2007-07-28 21:57

reporter   ~0014622

Some IRCds hide sensitive params from non-ops.. this is an option as well

stskeeps

2007-08-01 12:44

reporter   ~0014648

Fixed in r135

dmb

2007-08-03 01:44

reporter   ~0014657

I have qa tested this, and everything works correctly except that opers do not see the mode secondary variables when opered up. However, it works when using m_spy.so, so I am assuming it is following the the same trend +s and +k channels follow, so I believe it is tested and works.

Issue History

Date Modified Username Field Change
2007-07-28 06:24 CuttingEdge New Issue
2007-07-28 06:26 stskeeps QA => Not touched yet by developer
2007-07-28 06:26 stskeeps U4: Need for upstream patch => No need for upstream InspIRCd patch
2007-07-28 06:26 stskeeps U4: Upstream notification of bug => Not decided
2007-07-28 06:26 stskeeps U4: Contributor working on this => None
2007-07-28 06:26 stskeeps Status new => confirmed
2007-07-28 06:26 stskeeps Relationship added child of 0003417
2007-07-28 20:54 Shining Phoenix Note Added: 0014621
2007-07-28 21:57 Stealth Note Added: 0014622
2007-08-01 12:44 stskeeps QA Not touched yet by developer => Fixed by developer, needs QA testing
2007-08-01 12:44 stskeeps Status confirmed => resolved
2007-08-01 12:44 stskeeps Fixed in Version => 4.0-devel
2007-08-01 12:44 stskeeps Resolution open => fixed
2007-08-01 12:44 stskeeps Assigned To => stskeeps
2007-08-01 12:44 stskeeps Note Added: 0014648
2007-08-03 01:44 dmb Note Added: 0014657
2007-08-03 01:45 dmb QA Fixed by developer, needs QA testing => QA has accepted the fix