Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: The FPSC-IRCD.txt advisory
From: bre () NETVERJAR IS (Bjarni R. Einarsson)
Date: Tue, 9 Mar 1999 19:01:57 +0000


On 1999-03-07, 16:20:59 (-0800), syg FPSC wrote:

lines.  If you notice, it takes the '{' char and defines its uppercase char as
'['  as  along with defining '|' to '\', '}' to ']', and '~' to '^'. What this
means   is   thier  the  same  characters  in  channel  names  and  nicknames.

In RFC1459 chapter 2.2 says:

   Because of IRC's scandanavian origin, the characters {}| are
   considered to be the lower case equivalents of the characters []\,
   respectively.

So, what we have here is 75% a mIRC bug, not an IRCD bug.  I say 75% because
the RFC doesn't mention '~' and '^', which probably shouldn't be considered
equivalent by the server.

Did you (the authors of this advisory) bother to notify the maintainers of
these IRC servers and mIRC in particulaur?

(if RFC1459 has been superceded, just ignore me - but it hasn't, has it?)


Final Notes:
      IRCD coders and staff members of all networks and all IRCD versions need
to  check  your source for this bug and fix it before it gets abused... maybe it

IRC coders and staff members using mIRC deserve what they get. :-)  Happily,
the original advisory contained a work-around:  use BitchX, ircII or some
other properly implemented client.

--
Bjarni R. Einarsson                    [ PGP: 02764305 / B7A3AB89 ]
 bre () netverjar is -=- http://www.mmedia.is/~bre/ -=- Juggler () IRCnet

* http://www.europarl.eu.int/dg4/stoa/en/publi/166499/execsum.htm *
  Encrypt the covert narcotics, launder nuclear biotechno cash on
  the way to Swiss with your GSM phone - are you paranoid enough?



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]