]> jfr.im git - irc.git/blob - software/RELEASES/ircservices/achurch.org/services/lists/ircservices/2002/002844.html
rename -> *.git
[irc.git] / software / RELEASES / ircservices / achurch.org / services / lists / ircservices / 2002 / 002844.html
1 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
2 <HTML>
3 <HEAD>
4 <TITLE> [IRCServices] /ns ghost exploit
5 </TITLE>
6 <LINK REL="Index" HREF="index.html" >
7 <LINK REL="made" HREF="mailto:ircservices%40ircservices.za.net?Subject=%5BIRCServices%5D%20/ns%20ghost%20exploit&In-Reply-To=">
8 <META NAME="robots" CONTENT="index,nofollow">
9 <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
10 <LINK REL="Previous" HREF="002843.html">
11 <LINK REL="Next" HREF="002845.html">
12 </HEAD>
13 <BODY BGCOLOR="#ffffff">
14 <H1>[IRCServices] /ns ghost exploit</H1>
15 <B>Andrew Church</B>
16 <A HREF="mailto:ircservices%40ircservices.za.net?Subject=%5BIRCServices%5D%20/ns%20ghost%20exploit&In-Reply-To="
17 TITLE="[IRCServices] /ns ghost exploit">achurch at achurch.org
18 </A><BR>
19 <I>Thu Mar 14 10:43:00 PST 2002</I>
20 <P><UL>
21 <LI>Previous message: <A HREF="002843.html">[IRCServices] /ns ghost exploit
22 </A></li>
23 <LI>Next message: <A HREF="002845.html">[IRCServices] /ns ghost exploit
24 </A></li>
25 <LI> <B>Messages sorted by:</B>
26 <a href="date.html#2844">[ date ]</a>
27 <a href="thread.html#2844">[ thread ]</a>
28 <a href="subject.html#2844">[ subject ]</a>
29 <a href="author.html#2844">[ author ]</a>
30 </LI>
31 </UL>
32 <HR>
33 <!--beginarticle-->
34 <PRE> Services does not use SVSKILL in the first place, and does not allow
35 GHOST anyway without a password unless the calling user is on the access
36 list of the target nick _and_ the nick does not have the SECURE option set.
37 Have you modified Services?
38
39 --Andrew Church
40 <A HREF="http://www.ircservices.za.net/mailman/listinfo/ircservices">achurch at achurch.org</A>
41 <A HREF="http://achurch.org/">http://achurch.org/</A>
42
43 &gt;<i>Something I recently became aware of was users &quot;abusing&quot; the ghost command.
44 </I>&gt;<i>
45 </I>&gt;<i>When the ghost command is issued, Services will SVSKILL the user from the
46 </I>&gt;<i>network. However, the new trend appears to be setting up a notify script,
47 </I>&gt;<i>which will automatically ghost any user trying to use a given nickname.
48 </I>&gt;<i>This quickly became popular. How this came to my attention is that a new
49 </I>&gt;<i>user was trying to access the network but was repeatedly killed by the
50 </I>&gt;<i>ghost command.
51 </I>&gt;<i>
52 </I>&gt;<i>Use of &quot;kill immediate&quot; should be sufficient for those users who do not
53 </I>&gt;<i>want people using their nicknames and can be handled by services with a
54 </I>&gt;<i>nick change so I do not see use of the command in this manner as
55 </I>&gt;<i>beneficial.
56 </I>&gt;<i>
57 </I>&gt;<i>One way to remove this exploit which seems the least complex to actually
58 </I>&gt;<i>manage is to only trigger the ghost if the target is currently identified.
59 </I>&gt;<i>
60 </I>&gt;<i>This would mean that in the event a user got disconnected before they were
61 </I>&gt;<i>able to identify, they would be unable to remove a real 'ghost' on
62 </I>&gt;<i>reconnect with the ghost command, but they could use 'recover'
63 </I>&gt;<i>and 'release' instead. I believe that the 'recover' will &quot;guest&quot; a user
64 </I>&gt;<i>where NSForceNickChange is enabled.
65 </I>&gt;<i>
66 </I>&gt;<i>--
67 </I>&gt;<i>Mark.
68 </I>&gt;<i>
69 </I>&gt;<i>
70 </I>&gt;<i>------------------------------------------------------------------
71 </I>&gt;<i>To unsubscribe or change your subscription options, visit:
72 </I>&gt;<i><A HREF="http://www.ircservices.za.net/mailman/listinfo/ircservices">http://www.ircservices.za.net/mailman/listinfo/ircservices</A>
73 </I>
74 </PRE>
75
76 <!--endarticle-->
77 <HR>
78 <P><UL>
79 <!--threads-->
80 <LI>Previous message: <A HREF="002843.html">[IRCServices] /ns ghost exploit
81 </A></li>
82 <LI>Next message: <A HREF="002845.html">[IRCServices] /ns ghost exploit
83 </A></li>
84 <LI> <B>Messages sorted by:</B>
85 <a href="date.html#2844">[ date ]</a>
86 <a href="thread.html#2844">[ thread ]</a>
87 <a href="subject.html#2844">[ subject ]</a>
88 <a href="author.html#2844">[ author ]</a>
89 </LI>
90 </UL>
91
92 </body></html>