Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IRC and Firewalls
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Wed, 31 Jul 1996 20:38:55 +1000 (EST)
To: oolid @ acqic . org (Joseph L. Moll)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <2 . 2 . 32 . 19960708145142 . 006dc0ac @ mail . acquion . com> from "Joseph L. Moll" at Jul 8, 96 10:51:42 am

In some mail from Joseph L. Moll, sie said:
[...]
> In short, a machine outside your firewall can cause a machine inside your
> firewall to contact it as long as it is connected to the IRC server via the
> DCC connection protocol.  Once connected via DCC, files can be exchanged, etc.

Just to be picky, DCC is typically never initiated automatically and then
only if the user configures it thus so it is not possible for any single
machine to make any other do anything.  Well, the Unix clients are like this
(that I've used) and I trust that others haven't been silly enough to make
DCC work automatically...

Although I wouldn't trust this to always be the case, there is a disturbingly
large number of people who delight in making other users configure their
client in a way to turn them into security problems (or disasters),
including trojan scripts which have given people shell access with IRC used
as the "connection".



Follow-Ups:
References:
Indexed By Date Previous: Re: How secure is xinetd's binding to specific interfaces
From: gunni @ if . is (Gunnar Ingvi Thorisson)
Next: Re: Java security
From: "Simon J. Gerraty" <sjg @ quick . com . au>
Indexed By Thread Previous: Re: IRC and Firewalls
From: oolid @ acqic . org (Joseph L. Moll)
Next: Re: IRC and Firewalls
From: "Paul D. Robertson" <proberts @ clark . net>

Google
 
Search Internet Search www.greatcircle.com