]> jfr.im git - irc/quakenet/newserv.git/blobdiff - trojanscan/trojanscan.c
Actually try compiling the T fix.
[irc/quakenet/newserv.git] / trojanscan / trojanscan.c
index 42fbc6518ad573c2415959bf3751fa9ca80e849a..c68263418260eaa4065c9f00a4aa8eb21ba07143 100644 (file)
@@ -1,7 +1,7 @@
 /*
  * Trojanscan version 2
  *
- * Trojanscan  copyright (C) Chris Porter 2002-2005
+ * Trojanscan  copyright (C) Chris Porter 2002-2007
  * Newserv bits copyright (C) David Mansell 2002-2003
  * 
  * TODO: CHECK::
  */
 
 #include "trojanscan.h"
+#include "../lib/strlfunc.h"
+#include "../lib/version.h"
+
+MODULE_VERSION(TROJANSCAN_VERSION);
+
+void trojanscan_phrasematch(channel *chp, nick *sender, trojanscan_phrases *phrase, char messagetype, char *matchbuf);
+char *trojanscan_sanitise(char *input);
+void trojanscan_refresh_settings(void);
+
+#define TROJANSCAN_SETTING_SIZE 256
+#define TROJANSCAN_MAX_SETTINGS 50
+
+static struct {
+  char setting[TROJANSCAN_SETTING_SIZE];
+  char value[TROJANSCAN_SETTING_SIZE];
+} trojanscan_settings[TROJANSCAN_MAX_SETTINGS];
+
+static int settingcount = 0;
+static char *versionreply;
 
 void _init() {
   trojanscan_cmds = newcommandtree();
@@ -26,13 +45,13 @@ void _init() {
 
   addcommandtotree(trojanscan_cmds, "changelev", TROJANSCAN_ACL_STAFF | TROJANSCAN_ACL_OPER, 2, &trojanscan_changelev);
   addcommandtotree(trojanscan_cmds, "deluser", TROJANSCAN_ACL_TEAMLEADER | TROJANSCAN_ACL_OPER, 2, &trojanscan_deluser);
-  addcommandtotree(trojanscan_cmds, "mew", TROJANSCAN_ACL_STAFF | TROJANSCAN_ACL_OPER, 2, &trojanscan_mew);
+  addcommandtotree(trojanscan_cmds, "mew", TROJANSCAN_ACL_STAFF, 2, &trojanscan_mew);
   addcommandtotree(trojanscan_cmds, "status", TROJANSCAN_ACL_STAFF | TROJANSCAN_ACL_OPER, 0, &trojanscan_status);
   addcommandtotree(trojanscan_cmds, "listusers", TROJANSCAN_ACL_TEAMLEADER, 0, &trojanscan_listusers);
 
   addcommandtotree(trojanscan_cmds, "rehash", TROJANSCAN_ACL_WEBSITE, 0, &trojanscan_rehash);
 
-  addcommandtotree(trojanscan_cmds, "cat", TROJANSCAN_ACL_CAT | TROJANSCAN_ACL_OPER, 1, &trojanscan_cat);
+  addcommandtotree(trojanscan_cmds, "cat", TROJANSCAN_ACL_OPER, 1, &trojanscan_cat);
 
   addcommandtotree(trojanscan_cmds, "reschedule", TROJANSCAN_ACL_DEVELOPER | TROJANSCAN_ACL_OPER, 0, &trojanscan_reschedule);
   
@@ -84,6 +103,7 @@ void _fini(void) {
   for (i=0;i<TROJANSCAN_CLONE_TOTAL;i++)
     if(trojanscan_swarm[i].clone) {
       deregisterlocaluser(trojanscan_swarm[i].clone, NULL);
+      derefnode(iptree, trojanscan_swarm[i].fakeipnode);
       trojanscan_swarm[i].clone = NULL;
     }
   trojanscan_free_database();
@@ -178,20 +198,24 @@ void trojanscan_connect(void *arg) {
     return; /* PPA: module failed to load */
   }
   
-  trojanscan_database_query("CREATE TABLE phrases (id INT(10) PRIMARY KEY AUTO_INCREMENT, wormid INT(10) NOT NULL, phrase TEXT NOT NULL, priority INT(10) DEFAULT 0 NOT NULL, dateadded int(10))");
+  trojanscan_database_query("CREATE TABLE phrases (id INT(10) PRIMARY KEY AUTO_INCREMENT, wormid INT(10) NOT NULL, phrase TEXT NOT NULL, priority INT(10) DEFAULT 0 NOT NULL, dateadded int(10), disabled BOOL DEFAULT 0 NOT NULL)");
   trojanscan_database_query("CREATE TABLE worms (id INT(10) PRIMARY KEY AUTO_INCREMENT, wormname TEXT NOT NULL, glinetype INT DEFAULT 0, data text, hitmsgs BOOL DEFAULT 1, hitchans BOOL DEFAULT 0, epidemic BOOL DEFAULT 0, privinfo text)");
   trojanscan_database_query("CREATE TABLE logs (id INT(10) PRIMARY KEY AUTO_INCREMENT, userid INT(10) NOT NULL, act TEXT NOT NULL, description TEXT NOT NULL, ts TIMESTAMP)");
   trojanscan_database_query("CREATE TABLE channels (id INT(10) PRIMARY KEY AUTO_INCREMENT, channel VARCHAR(%d) NOT NULL, exempt BOOL DEFAULT 0)", CHANNELLEN);
   trojanscan_database_query("CREATE TABLE users (id INT(10) PRIMARY KEY AUTO_INCREMENT, authname VARCHAR(%d) NOT NULL, authlevel TINYINT(4) NOT NULL)", ACCOUNTLEN);
   trojanscan_database_query("CREATE TABLE hits (id INT(10) PRIMARY KEY AUTO_INCREMENT, nickname VARCHAR(%d) NOT NULL, ident VARCHAR(%d) NOT NULL, host VARCHAR(%d) NOT NULL, phrase INT(10) NOT NULL, ts TIMESTAMP, messagetype VARCHAR(1) NOT NULL DEFAULT 'm', glined BOOL DEFAULT 1)", NICKLEN, USERLEN, HOSTLEN);
-  trojanscan_database_query("CREATE TABLE settings (id INT(10) PRIMARY KEY AUTO_INCREMENT, setting VARCHAR(15) NOT NULL, value VARCHAR(15) NOT NULL)");
+  trojanscan_database_query("CREATE TABLE settings (id INT(10) PRIMARY KEY AUTO_INCREMENT, setting VARCHAR(255) NOT NULL UNIQUE, value VARCHAR(255) NOT NULL)");
   trojanscan_database_query("CREATE TABLE wwwlogs (id INT(10) PRIMARY KEY AUTO_INCREMENT, authid INT(10) NOT NULL, ip VARCHAR(15), action TEXT, ts TIMESTAMP)");
   trojanscan_database_query("CREATE TABLE unknownlog (id INT(10) PRIMARY KEY AUTO_INCREMENT, data TEXT, user VARCHAR(%d) NOT NULL, ts TIMESTAMP)", NICKLEN+USERLEN+HOSTLEN+3);
   
-  trojanscan_database_query("DELETE FROM settings");
+  trojanscan_database_query("DELETE FROM settings WHERE setting = 'rehash' OR setting = 'changed'");
   trojanscan_database_query("INSERT INTO settings (setting, value) VALUES ('rehash','0')");
   trojanscan_database_query("INSERT INTO settings (setting, value) VALUES ('changed','0')");
+
+  /* assumption: constants aren't supplied by someone evil */
+  trojanscan_database_query("INSERT INTO settings (setting, value) VALUES ('versionreply','" TROJANSCAN_DEFAULT_VERSION_REPLY "')");
   
+  trojanscan_refresh_settings();
   trojanscan_read_database(1);
  
   cp = findchannel(TROJANSCAN_OPERCHANNEL);
@@ -210,6 +234,7 @@ void trojanscan_connect(void *arg) {
       localgetops(trojanscan_nick, cp);
   }
 
+#ifdef TROJANSCAN_PEONCHANNEL
   cp = findchannel(TROJANSCAN_PEONCHANNEL);
   if (!cp) {
     localcreatechannel(trojanscan_nick, TROJANSCAN_PEONCHANNEL);
@@ -217,7 +242,8 @@ void trojanscan_connect(void *arg) {
     if(!localjoinchannel(trojanscan_nick, cp))
       localgetops(trojanscan_nick, cp);
   }
-  
+#endif
+
   freesstring(mnick);
   freesstring(myident);
   freesstring(myhost);
@@ -230,27 +256,63 @@ void trojanscan_connect(void *arg) {
   freesstring(dbport);
   trojanscan_registerclones(NULL);
   
-  trojanscan_initialschedule = scheduleoneshot(time(NULL) + 300, &trojanscan_fill_channels, NULL);
   trojanscan_rehashschedule = scheduleoneshot(time(NULL) + 60, &trojanscan_rehash_schedule, NULL);
 
 }
 
+char *trojanscan_get_setting(char *setting) {
+  int i;
+
+  for(i=0;i<settingcount;i++)
+    if(!strcmp(trojanscan_settings[i].setting, setting))
+      return trojanscan_settings[i].value;
+
+  return NULL;
+}
+
+void trojanscan_refresh_settings(void) {
+  trojanscan_database_res *res;
+  trojanscan_database_row sqlrow;
+  int i = 0;
+
+  if(trojanscan_database_query("SELECT setting, value FROM settings"))
+    return;
+
+  if(!(res = trojanscan_database_store_result(&trojanscan_sql)))
+    return;
+
+  if (trojanscan_database_num_rows(res) <= 0)
+    return;
+
+  while((sqlrow = trojanscan_database_fetch_row(res))) {
+    strlcpy(trojanscan_settings[i].setting, sqlrow[0], TROJANSCAN_SETTING_SIZE);
+    strlcpy(trojanscan_settings[i].value, sqlrow[1], TROJANSCAN_SETTING_SIZE);
+
+    trojanscan_sanitise(trojanscan_settings[i].value);
+
+    if(++i == TROJANSCAN_MAX_SETTINGS)
+      break;
+  }
+
+  settingcount = i;
+
+  trojanscan_database_free_result(res);
+
+  /* optimisation hack */
+  versionreply = trojanscan_get_setting("versionreply");
+}
+
 void trojanscan_rehash_schedule(void *arg) {
+  char *v;
   trojanscan_rehashschedule = scheduleoneshot(time(NULL) + 60, &trojanscan_rehash_schedule, NULL);
-  if (!(trojanscan_database_query("SELECT value FROM settings WHERE setting = 'rehash'"))) {
-    trojanscan_database_res *res;
-    if ((res = trojanscan_database_store_result(&trojanscan_sql))) {
-      if (trojanscan_database_num_rows(res) > 0) {
-        trojanscan_database_row sqlrow = trojanscan_database_fetch_row(res);
-        if (sqlrow && (sqlrow[0][0] == '1')) {
-          trojanscan_mainchanmsg("n: rehash initiated by website. . .");
-          trojanscan_read_database(0);
-        }
-      }
-      trojanscan_database_free_result(res);
-    }
-  } 
-    
+
+  trojanscan_refresh_settings();
+
+  v = trojanscan_get_setting("rehash");
+  if(v && v[0] == '1') {
+    trojanscan_mainchanmsg("n: rehash initiated by website. . .");
+    trojanscan_read_database(0);
+  }
 }
 
 void trojanscan_free_database(void) {
@@ -258,11 +320,12 @@ void trojanscan_free_database(void) {
   for(i=0;i<trojanscan_database.total_channels;i++)
     freesstring(trojanscan_database.channels[i].name);
   free(trojanscan_database.channels);
-  for(i=0;i<trojanscan_database.total_phrases;i++)
-    if (trojanscan_database.phrases[i].phrase) {
-      free(trojanscan_database.phrases[i].phrase);
-      free(trojanscan_database.phrases[i].hint);
-    }
+  for(i=0;i<trojanscan_database.total_phrases;i++) {
+    if (trojanscan_database.phrases[i].phrase)
+      pcre_free(trojanscan_database.phrases[i].phrase);
+    if (trojanscan_database.phrases[i].hint)
+      pcre_free(trojanscan_database.phrases[i].hint);
+  }
   free(trojanscan_database.phrases);
   for(i=0;i<trojanscan_database.total_worms;i++)
     freesstring(trojanscan_database.worms[i].name);
@@ -273,6 +336,16 @@ void trojanscan_free_database(void) {
   
 }
 
+char *trojanscan_sanitise(char *input) {
+  char *p;
+
+  for(p=input;*p;p++)
+    if(*p == '\r' || *p == '\n')
+      *p = '!';
+
+  return input;
+}
+
 sstring *trojanscan_getsstring(char *string, int length) {
   int i;
   
@@ -386,7 +459,7 @@ void trojanscan_read_database(int first_time) {
           if ((trojanscan_database.total_channels>0) && trojanscan_database.channels) {
             i = 0;
             while((sqlrow = trojanscan_database_fetch_row(res))) {
-              trojanscan_database.channels[i].name = trojanscan_getsstring(sqlrow[0], strlen(sqlrow[0]));
+              trojanscan_database.channels[i].name = trojanscan_getsstring(trojanscan_sanitise(sqlrow[0]), strlen(sqlrow[0]));
               trojanscan_database.channels[i].exempt = (sqlrow[1][0] == '1');
               i++;
             }
@@ -405,7 +478,7 @@ void trojanscan_read_database(int first_time) {
           i = 0;
           while((sqlrow = trojanscan_database_fetch_row(res))) {
             trojanscan_database.worms[i].id = atoi(sqlrow[0]);
-            trojanscan_database.worms[i].name = trojanscan_getsstring(sqlrow[1], strlen(sqlrow[1]));
+            trojanscan_database.worms[i].name = trojanscan_getsstring(trojanscan_sanitise(sqlrow[1]), strlen(sqlrow[1]));
             tempresult = atoi(sqlrow[2]);
             trojanscan_database.worms[i].glineuser = (tempresult == 0);
             trojanscan_database.worms[i].glinehost = (tempresult == 1);
@@ -428,7 +501,7 @@ void trojanscan_read_database(int first_time) {
     }
   } 
   
-  if (!(trojanscan_database_query("SELECT id, phrase, wormid FROM phrases ORDER BY priority DESC"))) {
+  if (!(trojanscan_database_query("SELECT id, phrase, wormid FROM phrases WHERE disabled = 0 ORDER BY priority DESC"))) {
     if ((res = trojanscan_database_store_result(&trojanscan_sql))) {
       trojanscan_database.total_phrases = trojanscan_database_num_rows(res);
       if (trojanscan_database.total_phrases > 0) {
@@ -440,9 +513,10 @@ void trojanscan_read_database(int first_time) {
             if (!(trojanscan_database.phrases[i].phrase = pcre_compile(sqlrow[1], PCRE_CASELESS, &error, &erroroffset, NULL))) {
               Error("trojanscan", ERR_WARNING, "Error compiling expression %s at offset %d: %s", sqlrow[1], erroroffset, error);
             } else {
-              if ((trojanscan_database.phrases[i].hint = pcre_study(trojanscan_database.phrases[i].phrase, 0, &error))) {
+              trojanscan_database.phrases[i].hint = pcre_study(trojanscan_database.phrases[i].phrase, 0, &error);
+              if (error) {
                 Error("trojanscan", ERR_WARNING, "Error studying expression %s: %s", sqlrow[1], error);
-                free(trojanscan_database.phrases[i].phrase);
+                pcre_free(trojanscan_database.phrases[i].phrase);
                 trojanscan_database.phrases[i].phrase = NULL;
               }
             }
@@ -455,7 +529,6 @@ void trojanscan_read_database(int first_time) {
   }
 
   trojanscan_database_query("UPDATE settings SET value = '0' where setting = 'rehash'");
-  
 }
 
 void trojanscan_log(nick *np, char *event, char *details, ...) {
@@ -479,8 +552,9 @@ void trojanscan_log(nick *np, char *event, char *details, ...) {
 void trojanscan_generateclone(void *arg) {
   int i, loops = 0, modes = UMODE_XOPER | UMODE_INV;
   char c_nick[NICKLEN+1], c_ident[USERLEN+1], c_host[HOSTLEN+1], c_real[REALLEN+1];
+  patricia_node_t *fakeip;
 
-  i = (int)arg;
+  i = (int)((long)arg);
 
   /* PPA: unlikely to be infinite */
   do {
@@ -497,11 +571,11 @@ void trojanscan_generateclone(void *arg) {
     trojanscan_genident(c_ident, trojanscan_minmaxrand(4, TROJANSCAN_MMIN(8, USERLEN)));
   
   if(trojanscan_hostmode) {
-    trojanscan_generatehost(c_host, HOSTLEN);
+    trojanscan_generatehost(c_host, HOSTLEN, &fakeip);
     if(!c_host[0])
-      trojanscan_genhost(c_host, HOSTLEN);
+      trojanscan_genhost(c_host, HOSTLEN, &fakeip);
   } else {
-    trojanscan_genhost(c_host, HOSTLEN);
+    trojanscan_genhost(c_host, HOSTLEN, &fakeip);
   }
   
   trojanscan_generaterealname(c_real, REALLEN);
@@ -509,6 +583,8 @@ void trojanscan_generateclone(void *arg) {
     trojanscan_genreal(c_real, trojanscan_minmaxrand(15, TROJANSCAN_MMIN(50, REALLEN)));
 
   trojanscan_swarm[i].clone = registerlocaluser(c_nick, c_ident, c_host, c_real, NULL, modes, &trojanscan_clonehandlemessages);
+  trojanscan_swarm[i].fakeipnode = fakeip;
+
   if(trojanscan_swarm[i].clone && !trojanscan_swarm_created) {
     nick *np = trojanscan_selectuser();
     if(np) /* select a 'random' sign on time for whois generation */
@@ -555,9 +631,11 @@ void trojanscan_registerclones(void *arg) {
   }
   
   for (i=0;i<TROJANSCAN_CLONE_TOTAL;i++)
-    trojanscan_generateclone((void *)i);
+    trojanscan_generateclone((void *)((long)i));
   trojanscan_mainchanmsg("n: swarm (%d clones) created.", TROJANSCAN_CLONE_TOTAL);
   trojanscan_swarm_created = 1;
+
+  trojanscan_initialschedule = scheduleoneshot(time(NULL) + 5, &trojanscan_fill_channels, NULL);
 }
 
 int trojanscan_status(void *sender, int cargc, char **cargv) {
@@ -694,6 +772,10 @@ int trojanscan_mew(void *sender, int cargc, char **cargv) {
   } else {
     trojanscan_reply(np, "Mewed at %s at %s.", cargv[1], np2->nick);
   }
+
+  if(!IsOper(np))
+    trojanscan_mainchanmsg("n: mew: %s %s (%s/%s)", cargv[1], cp?cp->index->name->content:np2->nick, np->nick, np->authname);
+
   return CMD_OK;
 }
 
@@ -902,7 +984,7 @@ int trojanscan_user_level_by_authname(char *authname) {
       if (trojanscan_database_num_rows(res) > 0) {
         trojanscan_database_row sqlrow = trojanscan_database_fetch_row(res);
         result = atoi(sqlrow[0]);
-        strncpy(authname, sqlrow[1], sl);
+        strlcpy(authname, sqlrow[1], sl + 1);
       }
       trojanscan_database_free_result(res);
     }
@@ -955,9 +1037,10 @@ struct trojanscan_clones *trojanscan_selectclone(char type) {
       if ((!rc->remaining) && (!rc->sitting)) {
         if (rc->clone) {
           deregisterlocaluser(rc->clone, NULL);
+          derefnode(iptree, rc->fakeipnode);
           rc->clone = NULL;
         }
-        trojanscan_generateclone((void *)rc->index);
+        trojanscan_generateclone((void *)((long)rc->index));
       }
     }
   }
@@ -966,6 +1049,20 @@ struct trojanscan_clones *trojanscan_selectclone(char type) {
 
 }
 
+/* hack hack hack */
+int trojanscan_nickbanned(trojanscan_clones *np, channel *cp) {
+  int ret;
+  patricia_node_t *realipnode = np->clone->ipnode;
+
+  np->clone->ipnode = np->fakeipnode;
+
+  ret = nickbanned(np->clone, cp);
+
+  np->clone->ipnode = realipnode;
+
+  return ret;
+}
+
 struct trojanscan_realchannels *trojanscan_allocaterc(char *chan) {
   struct trojanscan_realchannels *rc;
   struct trojanscan_clones *clonep;
@@ -1006,7 +1103,7 @@ struct trojanscan_realchannels *trojanscan_allocaterc(char *chan) {
       trojanscan_errorcode = 6;
       return NULL;
     }
-    if(!nickbanned(clonep->clone, cp))
+    if(!trojanscan_nickbanned(clonep, cp))
       break;
   } while (--attempts_left > 0);
 
@@ -1080,6 +1177,7 @@ int trojanscan_userjoin(void *sender, int cargc, char **cargv) {
 
 int trojanscan_rehash(void *sender, int cargc, char **cargv) {
   nick *np = (void *)sender;
+  trojanscan_refresh_settings();
   trojanscan_read_database(0);
   trojanscan_log(np, "rehash", "");
   trojanscan_reply(np, "Done.");
@@ -1297,7 +1395,7 @@ int trojanscan_add_ll(struct trojanscan_prechannels **head, struct trojanscan_pr
 void trojanscan_watch_clone_update(struct trojanscan_prechannels *hp, int count) {
   int i, j, marked;
   struct trojanscan_prechannels *lp;
-  struct trojanscan_templist *markedlist;
+  struct trojanscan_templist *markedlist = NULL;
 
   if(count > 0) {
     markedlist = (struct trojanscan_templist *)calloc(count, sizeof(struct trojanscan_templist));
@@ -1307,24 +1405,29 @@ void trojanscan_watch_clone_update(struct trojanscan_prechannels *hp, int count)
   
   for(i=0;i<trojanscan_activechans;i++) {
     marked = 0;    
-    for(lp=hp,j=0;j<count&&lp;j++,lp=lp->next) {
-      if(!markedlist[j].active && !lp->exempt && !ircd_strcmp(lp->name->content, trojanscan_chans[i].channel->content)) { /* we're already on the channel */
-        if(trojanscan_chans[i].watch_clone) {
-          markedlist[j].active = 1;
-          markedlist[j].watch_clone = trojanscan_chans[i].watch_clone;
-          lp->watch_clone = trojanscan_chans[i].watch_clone;
+    if(markedlist) {
+      for(lp=hp,j=0;j<count&&lp;j++,lp=lp->next) {
+        if(!markedlist[j].active && !lp->exempt && !ircd_strcmp(lp->name->content, trojanscan_chans[i].channel->content)) { /* we're already on the channel */
+          if(trojanscan_chans[i].watch_clone) {
+            markedlist[j].active = 1;
+            markedlist[j].watch_clone = trojanscan_chans[i].watch_clone;
+            lp->watch_clone = trojanscan_chans[i].watch_clone;
+          }
+          marked = 1;
+          break;
         }
-        marked = 1;
-        break;
       }
     }
     if(!marked && trojanscan_chans[i].watch_clone) {
       channel *cp = findchannel(trojanscan_chans[i].channel->content);
       if(cp)
-        localpartchannel(trojanscan_chans[i].watch_clone->clone, cp);
+        localpartchannel(trojanscan_chans[i].watch_clone->clone, cp, NULL);
     }
   }
   
+  if(!markedlist)
+    return;
+
   for(j=0,lp=hp;j<count&&lp;j++,lp=lp->next) {
     if((!markedlist[j].active || !markedlist[j].watch_clone) && !lp->exempt) {
       channel *cp = findchannel(lp->name->content);
@@ -1334,7 +1437,7 @@ void trojanscan_watch_clone_update(struct trojanscan_prechannels *hp, int count)
           lp->watch_clone = trojanscan_selectclone(TROJANSCAN_WATCH_CLONES);      
           if(!lp->watch_clone)
             break;
-          if(!nickbanned(lp->watch_clone->clone, cp)) {
+          if(!trojanscan_nickbanned(lp->watch_clone, cp)) {
             if(localjoinchannel(lp->watch_clone->clone, cp))
               lp->watch_clone = NULL;
             break;
@@ -1438,7 +1541,7 @@ void trojanscan_dopart(void *arg) {
   }
   
   if (rc->clone->clone && (!(rc->donotpart)))
-    localpartchannel(rc->clone->clone, rc->chan);
+    localpartchannel(rc->clone->clone, rc->chan, NULL);
 
   rc->clone->sitting--;
 
@@ -1469,7 +1572,7 @@ void trojanscan_donickchange(void *arg) { /* just incase I choose to make this s
       } else {
         trojanscan_gennick(c_nick, trojanscan_minmaxrand(7, TROJANSCAN_MMIN(13, NICKLEN)));
       }
-    } while (c_nick && (getnickbynick(c_nick) != NULL));
+    } while (c_nick[0] && (getnickbynick(c_nick) != NULL));
 
     renamelocaluser(clone->clone, c_nick);
   }
@@ -1537,6 +1640,8 @@ void trojanscan_handlemessages(nick *target, int messagetype, void **args) {
 
       /* Split the line into params */
       cargc = splitline((char *)args[1], cargv, 50, 0);
+      if(cargc == 0 || !cargv[0])
+        return;
 
       cmd=findcommandintree(trojanscan_cmds, cargv[0], 1);
       if (!cmd) {
@@ -1620,13 +1725,13 @@ char trojanscan_getmtfrommessagetype(int input) {
 }
 
 void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args) {
-  char *pretext = NULL, etext[TROJANSCAN_QUERY_TEMP_BUF_SIZE], enick[TROJANSCAN_QUERY_TEMP_BUF_SIZE], eident[TROJANSCAN_QUERY_TEMP_BUF_SIZE], ehost[TROJANSCAN_QUERY_TEMP_BUF_SIZE], text[513], detected = 0;
+  char *pretext = NULL, text[513];
   nick *sender;
   struct trojanscan_realchannels *rp;
   struct trojanscan_rejoinlist *rj;
   unsigned int i, len;
   struct trojanscan_worms *worm;
-  int vector[30];
+  int vector[30], detected = 0;
   char mt = trojanscan_getmtfrommessagetype(messagetype);
   char *channel_name;
 
@@ -1672,7 +1777,7 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
               sendnoticetouser(target, sender, "\001VERSION T clone, though since T is currently gone you'll have to version me again in a minute for confirmation.\001");
             }
           } else {
-            sendnoticetouser(target, sender,  "\001VERSION " TROJANSCAN_CLONE_VERSION_REPLY "\001");
+            sendnoticetouser(target, sender,  "\001VERSION %s\001", versionreply);
           }
         
           return;
@@ -1710,106 +1815,23 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
            ) {
           int pre = pcre_exec(trojanscan_database.phrases[i].phrase, trojanscan_database.phrases[i].hint, text, len, 0, 0, vector, 30);
           if(pre >= 0) {
-            char glinemask[HOSTLEN + USERLEN + NICKLEN + 4];
-            char *userbit;
-            host *hp;
-            unsigned int j, usercount, frequency;
-            char ip[TROJANSCAN_IPLEN];
-            int glining = 1;
-            channel *chp = (channel *)args[1];
-            
-            nick *np = NULL; /* sigh at warnings */
-            
-            detected = 1;
-            
-            trojanscan_database.detections++;
-            
-            if (!(hp=findhost(sender->host->name->content))) {
-              trojanscan_mainchanmsg("w: user %s!%s@%s triggered infection monitor, yet no hosts found at stage 1 -- worm: %s", sender->nick, sender->ident, sender->host->name->content, worm->name->content);
-              break;
-            } 
-
-            usercount = 0; /* stupid warnings */
-            if (worm->monitor) {
-              glining = 0;
-              usercount = -1;
-            } else if (worm->glinehost && (hp->clonecount <= TROJANSCAN_MAX_HOST_GLINE)) {
-              snprintf(glinemask, sizeof(glinemask) - 1, "*@%s", trojanscan_iptostr(ip, sizeof(ip) - 1, sender->ipaddress));
-              usercount = hp->clonecount;
-            }
-            else if (worm->glineuser || (worm->glinehost && hp->clonecount > TROJANSCAN_MAX_HOST_GLINE)) {
-              userbit = sender->ident;
-              if(userbit[0] == '~')
-                userbit++;
-              snprintf(glinemask, sizeof(glinemask) - 1, "*%s@%s", userbit, trojanscan_iptostr(ip, sizeof(ip) - 1, sender->ipaddress));
-              for (j=0;j<NICKHASHSIZE;j++) {
-                for (np=nicktable[j];np;np=np->next) {
-                  if ((np->host==hp) && (!ircd_strcmp(np->ident,sender->ident)))
-                    usercount++;
-                }
-              }
-            }
-            
-            if (!usercount) {
-              trojanscan_mainchanmsg("w: user %s!%s@%s triggered infection monitor, yet no hosts found at stage 2 -- worm: %s", sender->nick, sender->ident, sender->host->name->content, worm->name->content);
-              break;
-            }
-             
-            if (glining && (usercount > trojanscan_maxusers)) {
-              trojanscan_mainchanmsg("w: not glining %s!%s@%s due to too many users (%d) with mask: *!%s -- worm: %s)", sender->nick, sender->ident, sender->host->name->content, usercount, glinemask, worm->name->content);
-              break;
-            }
-
-            if (glining && !worm->datalen) {
-              trojanscan_mainchanmsg("w: not glining %s!%s@%s due to too lack of removal data with mask: *!%s (%d users) -- worm: %s)", sender->nick, sender->ident, sender->host->name->content, glinemask, usercount, worm->name->content);
-              break;
-            }
-                        
-            trojanscan_database_escape_string(enick, sender->nick, strlen(sender->nick));
-            trojanscan_database_escape_string(eident, sender->ident, strlen(sender->ident));
-            trojanscan_database_escape_string(ehost, sender->host->name->content, sender->host->name->length);
-            
-            frequency = 1;
+            char matchbuf[513];
+            matchbuf[0] = 0;
+            matchbuf[512] = 0; /* hmm */
+    
+            if(pre > 1)
+              if(pcre_copy_substring(text, vector, pre, 1, matchbuf, sizeof(matchbuf) - 1) <= 0)
+                matchbuf[0] = 0;
             
-            if (!(trojanscan_database_query("SELECT COUNT(*) FROM hits WHERE glined = %d AND host = '%s'", glining, ehost))) {
-              trojanscan_database_res *res;
-              if ((res = trojanscan_database_store_result(&trojanscan_sql))) {
-                trojanscan_database_row sqlrow;
-                if ((trojanscan_database_num_rows(res) > 0) && (sqlrow = trojanscan_database_fetch_row(res)))
-                  frequency = atoi(sqlrow[0]) + 1;
-                trojanscan_database_free_result(res);
-              }
-            } 
-
-            if (!glining) {
-              char matchbuf[513];
-              matchbuf[0] = 0;
-              matchbuf[512] = 0; /* hmm */
-              
-              if(pre > 1)
-                if (pcre_copy_substring(text, vector, pre, 1, matchbuf, sizeof(matchbuf) - 1) <= 0)
-                  matchbuf[0] = 0;
-              
-              trojanscan_mainchanmsg("m: t: %c u: %s!%s@%s%s%s w: %s %s%s", mt, sender->nick, sender->ident, sender->host->name->content, mt=='N'||mt=='M'?" #: ":"", mt=='N'||mt=='M'?chp->index->name->content:"", worm->name->content, matchbuf[0]?" --: ":"", matchbuf[0]?matchbuf:"");
-              trojanscan_peonchanmsg("m: t: %c u: %s!%s@%s%s%s%s w: %s %s%s", mt, sender->nick, sender->ident, (IsHideHost(sender)&&IsAccount(sender))?sender->authname:sender->host->name->content, (IsHideHost(sender)&&IsAccount(sender))?"."HIS_HIDDENHOST:"", mt=='N'||mt=='M'?" #: ":"", mt=='N'||mt=='M'?chp->index->name->content:"", worm->name->content, matchbuf[0]?" --: ":"", matchbuf[0]?matchbuf:"");
-            } else {
-              int glinetime = TROJANSCAN_FIRST_OFFENSE * frequency * (worm->epidemic?TROJANSCAN_EPIDEMIC_MULTIPLIER:1);
-              if(glinetime > 7 * 24)
-                glinetime = 7 * 24; /* can't set glines over 7 days with normal non U:lined glines */
+            trojanscan_phrasematch(args[1], sender, &trojanscan_database.phrases[i], mt, matchbuf);
 
-              trojanscan_database_query("INSERT INTO hits (nickname, ident, host, phrase, messagetype, glined) VALUES ('%s', '%s', '%s', %d, '%c', %d)", enick, eident, ehost, trojanscan_database.phrases[i].id, mt, glining);          
-              trojanscan_database.glines++;
-              
-              irc_send("%s GL * +%s %d %d :You (%s!%s@%s) are infected with a trojan (%s), see %s%d for details - banned for %d hours\r\n", mynumeric->content, glinemask, glinetime * 3600, getnettime(), sender->nick, sender->ident, sender->host->name->content, worm->name->content, TROJANSCAN_URL_PREFIX, worm->id, glinetime);
-
-              trojanscan_mainchanmsg("g: *!%s t: %c u: %s!%s@%s%s%s c: %d w: %s%s f: %d", glinemask, mt, sender->nick, sender->ident, sender->host->name->content, mt=='N'||mt=='M'?" #: ":"", mt=='N'||mt=='M'?chp->index->name->content:"", usercount, worm->name->content, worm->epidemic?"(E)":"", frequency);
-            }
-            
+            detected = 1;
             break;
           }
         }
       }
       if (!detected && (mt != 'N') && (mt != 'M')) {
+        char etext[TROJANSCAN_QUERY_TEMP_BUF_SIZE], enick[TROJANSCAN_QUERY_TEMP_BUF_SIZE], eident[TROJANSCAN_QUERY_TEMP_BUF_SIZE], ehost[TROJANSCAN_QUERY_TEMP_BUF_SIZE];
         trojanscan_database_escape_string(etext, text, len);
         trojanscan_database_escape_string(enick, sender->nick, strlen(sender->nick));
         trojanscan_database_escape_string(eident, sender->ident, strlen(sender->ident));
@@ -1824,7 +1846,7 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
       for (i=0;i<TROJANSCAN_CLONE_TOTAL;i++) {
         if (trojanscan_swarm[i].clone == target) {
           
-          scheduleoneshot(time(NULL)+1, &trojanscan_generateclone, (void *)i);
+          scheduleoneshot(time(NULL)+1, &trojanscan_generateclone, (void *)((long)i));
           if(i >= TROJANSCAN_CLONE_MAX) {
             int j;
             for(j=0;j<trojanscan_activechans;j++)
@@ -1835,6 +1857,7 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
               if ((rp->clone == &(trojanscan_swarm[i])))
                 rp->donotpart = 1;
           }
+          derefnode(iptree, trojanscan_swarm[i].fakeipnode);
           trojanscan_swarm[i].clone = NULL;
           trojanscan_swarm[i].remaining = 0; /* bah */
           break;
@@ -1883,7 +1906,7 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
               return;
             }
 
-            rj->clone = target;
+            rj->clone = rp->clone;
             rj->next = trojanscan_schedulerejoins;
             trojanscan_schedulerejoins = rj;
 
@@ -1896,6 +1919,90 @@ void trojanscan_clonehandlemessages(nick *target, int messagetype, void **args)
   }
 }
 
+void trojanscan_phrasematch(channel *chp, nick *sender, trojanscan_phrases *phrase, char messagetype, char *matchbuf) {
+  char glinemask[HOSTLEN + USERLEN + NICKLEN + 4], enick[TROJANSCAN_QUERY_TEMP_BUF_SIZE], eident[TROJANSCAN_QUERY_TEMP_BUF_SIZE], ehost[TROJANSCAN_QUERY_TEMP_BUF_SIZE];
+  char *userbit;
+  unsigned int j, usercount, frequency;
+  int glining = 1;
+  struct trojanscan_worms *worm = phrase->worm;
+
+  nick *np = NULL; /* sigh at warnings */
+  
+  trojanscan_database.detections++;
+  
+  usercount = 0;
+  if (worm->monitor) {
+    glining = 0;
+    usercount = -1;
+  } else if (worm->glinehost && (sender->ipnode->usercount <= TROJANSCAN_MAX_HOST_GLINE)) {
+    snprintf(glinemask, sizeof(glinemask) - 1, "*@%s", IPtostr(sender->p_ipaddr));
+    for (j=0;j<NICKHASHSIZE;j++)
+      for (np=nicktable[j];np;np=np->next)
+        if (np->ipnode==sender->ipnode)
+          usercount++;
+  } else if (worm->glineuser || (worm->glinehost && sender->ipnode->usercount > TROJANSCAN_MAX_HOST_GLINE)) {
+    userbit = sender->ident;
+/*
+    if(userbit[0] == '~')
+      userbit++;
+*/
+    snprintf(glinemask, sizeof(glinemask) - 1, "%s@%s", userbit, IPtostr(sender->p_ipaddr));
+    for (j=0;j<NICKHASHSIZE;j++)
+      for (np=nicktable[j];np;np=np->next)
+        if ((np->ipnode==sender->ipnode) && (!ircd_strcmp(np->ident,sender->ident)))
+          usercount++;
+  }
+  
+  if (!usercount) {
+    trojanscan_mainchanmsg("w: user %s!%s@%s triggered infection monitor, yet no hosts found at stage 2 -- worm: %s", sender->nick, sender->ident, sender->host->name->content, worm->name->content);
+    return;
+  }
+   
+  if (glining && (usercount > trojanscan_maxusers)) {
+    trojanscan_mainchanmsg("w: not glining %s!%s@%s due to too many users (%d) with mask: *!%s -- worm: %s)", sender->nick, sender->ident, sender->host->name->content, usercount, glinemask, worm->name->content);
+    return;
+  }
+
+  if (glining && !worm->datalen) {
+    trojanscan_mainchanmsg("w: not glining %s!%s@%s due to too lack of removal data with mask: *!%s (%d users) -- worm: %s)", sender->nick, sender->ident, sender->host->name->content, glinemask, usercount, worm->name->content);
+    return;
+  }
+    
+  trojanscan_database_escape_string(enick, sender->nick, strlen(sender->nick));
+  trojanscan_database_escape_string(eident, sender->ident, strlen(sender->ident));
+  trojanscan_database_escape_string(ehost, sender->host->name->content, sender->host->name->length);
+  
+  frequency = 1;
+  
+  if (!(trojanscan_database_query("SELECT COUNT(*) FROM hits WHERE glined = %d AND host = '%s'", glining, ehost))) {
+    trojanscan_database_res *res;
+    if ((res = trojanscan_database_store_result(&trojanscan_sql))) {
+      trojanscan_database_row sqlrow;
+      if ((trojanscan_database_num_rows(res) > 0) && (sqlrow = trojanscan_database_fetch_row(res)))
+        frequency = atoi(sqlrow[0]) + 1;
+      trojanscan_database_free_result(res);
+    }
+  } 
+
+  if (!glining) {
+    trojanscan_mainchanmsg("m: t: %c u: %s!%s@%s%s%s w: %s p: %d %s%s", messagetype, sender->nick, sender->ident, sender->host->name->content, messagetype=='N'||messagetype=='M'?" #: ":"", messagetype=='N'||messagetype=='M'?chp->index->name->content:"", worm->name->content, phrase->id, matchbuf[0]?" --: ":"", matchbuf[0]?matchbuf:"");
+#ifdef TROJANSCAN_PEONCHANNEL
+    trojanscan_peonchanmsg("m: t: %c u: %s!%s@%s%s%s%s w: %s %s%s", messagetype, sender->nick, sender->ident, (IsHideHost(sender)&&IsAccount(sender))?sender->authname:sender->host->name->content, (IsHideHost(sender)&&IsAccount(sender))?"."HIS_HIDDENHOST:"", messagetype=='N'||messagetype=='M'?" #: ":"", messagetype=='N'||messagetype=='M'?chp->index->name->content:"", worm->name->content, matchbuf[0]?" --: ":"", matchbuf[0]?matchbuf:"");
+#endif
+  } else {
+    int glinetime = TROJANSCAN_FIRST_OFFENSE * frequency * (worm->epidemic?TROJANSCAN_EPIDEMIC_MULTIPLIER:1);
+    if(glinetime > 7 * 24)
+      glinetime = 7 * 24; /* can't set glines over 7 days with normal non U:lined glines */
+
+    trojanscan_database_query("INSERT INTO hits (nickname, ident, host, phrase, messagetype, glined) VALUES ('%s', '%s', '%s', %d, '%c', %d)", enick, eident, ehost, phrase->id, messagetype, glining);
+    trojanscan_database.glines++;
+    
+    irc_send("%s GL * +%s %d :You (%s!%s@%s) are infected with a trojan (%s/%d), see %s%d for details - banned for %d hours\r\n", mynumeric->content, glinemask, glinetime * 3600, sender->nick, sender->ident, sender->host->name->content, worm->name->content, phrase->id, TROJANSCAN_URL_PREFIX, worm->id, glinetime);
+
+    trojanscan_mainchanmsg("g: *!%s t: %c u: %s!%s@%s%s%s c: %d w: %s%s p: %d f: %d", glinemask, messagetype, sender->nick, sender->ident, sender->host->name->content, messagetype=='N'||messagetype=='M'?" #: ":"", messagetype=='N'||messagetype=='M'?chp->index->name->content:"", usercount, worm->name->content, worm->epidemic?"(E)":"", phrase->id, frequency);
+  }
+}
+            
 void trojanscan_rejoin_channel(void *arg) {
   struct trojanscan_rejoinlist *rj2, *lrj, *rj = (struct trojanscan_rejoinlist *)arg;
   
@@ -1908,10 +2015,10 @@ void trojanscan_rejoin_channel(void *arg) {
       rj->rp->donotpart = 1; /* we were the last user on the channel, so we need to be VERY careful freeing it */
     } else {
       if(!rj->rp->donotpart && !rj->rp->kickedout) { /* check we're allowed to join channels (not killed), and we're the last one to join */
-        if (nickbanned(rj->clone, cp)) {
+        if (trojanscan_nickbanned(rj->clone, cp)) {
           rj->rp->donotpart = 1;
         } else {
-          localjoinchannel(rj->clone, cp);
+          localjoinchannel(rj->clone->clone, cp);
         }
       }
     }
@@ -1967,6 +2074,7 @@ void trojanscan_mainchanmsg(char *message, ...) {
   sendmessagetochannel(trojanscan_nick, cp, "%s", buf);
 }
 
+#ifdef TROJANSCAN_PEONCHANNEL
 void trojanscan_peonchanmsg(char *message, ...) {
   char buf[513];
   va_list va;
@@ -1983,6 +2091,7 @@ void trojanscan_peonchanmsg(char *message, ...) {
   
   sendmessagetochannel(trojanscan_nick, cp, "%s", buf);
 }
+#endif
 
 int trojanscan_minmaxrand(float min, float max) {
   return (int)((max-min+1)*rand()/(RAND_MAX+min))+min;
@@ -2053,9 +2162,10 @@ void trojanscan_genident(char *ptc, char size) {
   ptc[i] = '\0';
 }
 
-void trojanscan_genhost(char *ptc, char size) {
+void trojanscan_genhost(char *ptc, char size, patricia_node_t **fakeipnode) {
   int dots = trojanscan_minmaxrand(2, 5), i, dotexist = 0, cur;
-  
+  struct irc_in_addr ipaddress;
+
   while (!dotexist) {
     for (i=0;i<size;i++) {
       ptc[i] = trojanscan_genchar(0);
@@ -2075,6 +2185,13 @@ void trojanscan_genhost(char *ptc, char size) {
     }
   }
   ptc[i] = '\0';
+
+  memset(&ipaddress, 0, sizeof(ipaddress));
+  ((unsigned short *)(ipaddress.in6_16))[5] = 65535;
+  ((unsigned short *)(ipaddress.in6_16))[6] = trojanscan_minmaxrand(0, 65535);
+  ((unsigned short *)(ipaddress.in6_16))[7] = trojanscan_minmaxrand(0, 65535);
+
+  *fakeipnode = refnode(iptree, &ipaddress, PATRICIA_MAXBITS);
 }
 
 void trojanscan_genreal(char *ptc, char size) {
@@ -2170,15 +2287,43 @@ nick *trojanscan_selectuser(void) {
   return NULL;
 }
 
-void trojanscan_generatehost(char *buf, int maxsize) {
+host *trojanscan_selecthost(void) {
+  int target = trojanscan_minmaxrand(0, 500), loops = 150, j;
+  host *hp;
+  do {
+    for (j=trojanscan_minmaxrand(0, HOSTHASHSIZE-1);j<HOSTHASHSIZE;j++)
+      for(hp=hosttable[j];hp;hp=hp->next)
+        if (!--target)
+          return hp;
+  } while(--loops > 0);
+
+  return NULL;
+}
+
+void trojanscan_generatehost(char *buf, int maxsize, patricia_node_t **fakeip) {
+  struct irc_in_addr ipaddress;
+
   if(TROJANSCAN_HOST_MODE == TROJANSCAN_STEAL_HOST) {
-    nick *np;
+    host *hp;
     int loops = 20;
+
     buf[0] = '\0';
+
     do {
-      np = trojanscan_selectuser();
-      if(np && !trojanscan_isip(np->host->name->content)) {
-        strncpy(buf, np->host->name->content, maxsize);
+      hp = trojanscan_selecthost();
+      if(hp && (hp->clonecount <= TROJANSCAN_MAX_CLONE_COUNT) && !trojanscan_isip(hp->name->content)) {
+        strlcpy(buf, hp->name->content, maxsize + 1);
+        if(hp->nicks) {
+          *fakeip = hp->nicks->ipnode;
+         patricia_ref_prefix(hp->nicks->ipnode->prefix);
+        } else {
+          memset(&ipaddress, 0, sizeof(ipaddress));
+         ((unsigned short *)(ipaddress.in6_16))[5] = 65535; 
+          ((unsigned short *)(ipaddress.in6_16))[6] = trojanscan_minmaxrand(0, 65535);
+          ((unsigned short *)(ipaddress.in6_16))[7] = trojanscan_minmaxrand(0, 65535);
+
+          *fakeip = refnode(iptree, &ipaddress, PATRICIA_MAXBITS);
+        }
         break;
       }
     } while(--loops > 0);
@@ -2217,6 +2362,13 @@ void trojanscan_generatehost(char *buf, int maxsize) {
     buf[a] = '\0';
     free(choices);
     free(lengths);
+
+    memset(&ipaddress, 0, sizeof(ipaddress));
+    ((unsigned short *)(ipaddress.in6_16))[5] = 65535;
+    ((unsigned short *)(ipaddress.in6_16))[6] = trojanscan_minmaxrand(0, 65535);
+    ((unsigned short *)(ipaddress.in6_16))[7] = trojanscan_minmaxrand(0, 65535);
+
+    *fakeip = refnode(iptree, &ipaddress, PATRICIA_MAXBITS);
   }
 }
 
@@ -2246,14 +2398,14 @@ void trojanscan_generateident(char *buf, int maxsize) {
   nick *np = trojanscan_selectuser();
   buf[0] = '\0';
   if(np)
-    strncpy(buf, np->ident, maxsize);
+    strlcpy(buf, np->ident, maxsize + 1);
 }
 
 void trojanscan_generaterealname(char *buf, int maxsize) {
   nick *np = trojanscan_selectuser();
   buf[0] = '\0';
   if(np)
-    strncpy(buf, np->realname->name->content, maxsize);
+    strlcpy(buf, np->realname->name->content, maxsize + 1);
 }
 
 void trojanscan_database_close(void) {