Date: Sun, 28 Oct 2001 09:24:38 +0800
From: Raymond <[EMAIL PROTECTED]>
Subject: Re: IRC security (was Re: One size fits all (was Re: [LIB]
  Libretto Beer Club, Middle East))

At 10:19 AM 27/10/2001 -0700, you wrote:
>Date: Sat, 27 Oct 2001 09:59:54 -0500 (CDT)
>From: Tina Bird <[EMAIL PROTECTED]>
>Subject: Re: One size fits all (was Re: [LIB] Libretto Beer Club, Middle East
> chapter)

...

>On a slightly more serious note -- not to drop a rain cloud
>on the IRC initiative, but if you join the channel, you'll want
>to be REALLY REALLY careful about how you install and use the
>client on either Windows or Linux.  Both mIRC and BitchX have
>horrible reputations in the security world for their tendency
>to provide unintended access to random users on IRC. Security
>geeks like myself avoid IRC altogether...but hey, they pay me
>to be paranoid.  For more information, search on either
>BitchX or mIRC at http://www.securityfocus.com

OK first things first, I'd like to point out that in my brief scan of the articles 
that a search on mIRC returns at securityfocus, the ONLY problems that occur stem from 
users doing dumb things. These include running scripts from unknown sources 
(unfortunately many users don't realize that running a script has the same ability to 
cause damage as running an unknown executable) or users autoaccepting files (or 
manually accepting files) then running them without thinking twice. Both these can 
happen equally through email or newsgroups through attachments (just look at the love 
bug - does that mean we all shouldn't use email? ... and before someone points out, 
the love bug is designed for OE but absent minded users can still have problems on any 
Windows based email program if they run the attachment anyway). As one of the users on 
SecurityFocus said, "Ultimately, you just can't trust scripts that other people hand 
you without looking at the code yourself.. this is just common sense.".

I dunno about BitchX as I haven't used it much (I just mentioned it for any Linux 
devotees out there) but I do know that versions of mIRC newer than about a year or 2 
at least are quite safe as long as you don't do dumb things like auto-accept 
everything and you don't run scripts from unknown sources ("Polaris" is a classical 
example of a script which many people use but not so many realize has a back door). In 
fact, the golden rule should really be don't run scripts at all - if you need a 
shortcut write it yourself. If you don't know enough about mIRC to do so and you use 
it enough to need something like that then perhaps its time to learn - its very very 
easy anyway.

A DEFAULT installation of mIRC (no scripts, no tweaking of settings except for 
inputting details) is extremely safe, certainly more so than a default install of 
Outlook Express, as it warns you about anything and everything anyway and won't do 
things behind your back, the worst thing about it is that anyone on the same network 
can find out your IP address so if you really annoy them (or if they're up to no good) 
they can use that to mount an unrelated attack on your computer (but then that comes 
down to what other software you have on your computer). Note that such an attack can 
be mounted if they get your IP from a newsgroup post, an email or even a web based 
newsgroup - its not a problem specific to IRC.

IMHO this is a small risk as NOT using IRC effectively becomes security by obscurity, 
not something that lasts very long with the number of people (or compromised machines) 
that just randomly scan for IPs to attack anyway and the number of places that record 
your IP address for public viewing. Even if you don't use IRC you should really take 
precautions like running an up-to-date virus scanner, don't enable sharing on your 
external interface, keep your installation well patched, run a personal firewall 
(www.zonelabs.com has a freeware one) and so on. These measures will also counter 
anything a malicious IRC user could do to you as well short of a flood attack (if 
you're on a dialup modem or if the adversary has an amplifying network), but that 
could happen with any medium anyway (for instance many web based newsgroups and 
newsgroups in general display your last known IP address as do some email services as 
anyone who's recieved a direct email from me would know). 

So thats my 2 cents ... just like anything else on the Internet, as long as you don't 
do dumb things, IRC is just as safe as any near-real-time communications channel on 
the Internet, except its considerably more real time than others. Don't let Tina 
frighten you from visiting #Libretto!


- Raymond


P.S. in case anyone is interested, in one of my many roles in life, I too am a 
security geek ... locking down computers such that they can withstand attacks from 
University level Computer Science students gets interesting ;-)

---


/~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\
|                 | "Does fuzzy logic tickle?"                |
|   ___           | "My HDD has no reverse. How do I backup?" | 
|  /__/           +-------------------------------------------|
| /  \ a y b o t  |          [EMAIL PROTECTED]             |
|                 |          HTTP://www.raybot.net            |
| ICQ: 31756092   |   Need help? Visit #Windows98 on DALNet!  |
\~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~/




**************************************************************
http://libretto.basiclink.com - Libretto mailing list
http://libretto.basiclink.com/archive - Archives
http://www.picante.com/~gtaylor/portable/faq.html - FAQ
                 -------TO UNSUBSCRIBE-------
Reply to any of the list messages. The reply mail should be
addressed to: [EMAIL PROTECTED] - Then replace any text
on the message's subject line: cmd:unsubscribe
              --------TO UNSUBSCRIBE DIGEST------
Do above but with this on subject line: cmd:unsubscribe digest
**************************************************************

Reply via email to