Date: Sun, 28 Oct 2001 09:24:38 +0800 From: Raymond <[EMAIL PROTECTED]> Subject: Re: IRC security (was Re: One size fits all (was Re: [LIB] Libretto Beer Club, Middle East))
At 10:19 AM 27/10/2001 -0700, you wrote: >Date: Sat, 27 Oct 2001 09:59:54 -0500 (CDT) >From: Tina Bird <[EMAIL PROTECTED]> >Subject: Re: One size fits all (was Re: [LIB] Libretto Beer Club, Middle East > chapter) ... >On a slightly more serious note -- not to drop a rain cloud >on the IRC initiative, but if you join the channel, you'll want >to be REALLY REALLY careful about how you install and use the >client on either Windows or Linux. Both mIRC and BitchX have >horrible reputations in the security world for their tendency >to provide unintended access to random users on IRC. Security >geeks like myself avoid IRC altogether...but hey, they pay me >to be paranoid. For more information, search on either >BitchX or mIRC at http://www.securityfocus.com OK first things first, I'd like to point out that in my brief scan of the articles that a search on mIRC returns at securityfocus, the ONLY problems that occur stem from users doing dumb things. These include running scripts from unknown sources (unfortunately many users don't realize that running a script has the same ability to cause damage as running an unknown executable) or users autoaccepting files (or manually accepting files) then running them without thinking twice. Both these can happen equally through email or newsgroups through attachments (just look at the love bug - does that mean we all shouldn't use email? ... and before someone points out, the love bug is designed for OE but absent minded users can still have problems on any Windows based email program if they run the attachment anyway). As one of the users on SecurityFocus said, "Ultimately, you just can't trust scripts that other people hand you without looking at the code yourself.. this is just common sense.". I dunno about BitchX as I haven't used it much (I just mentioned it for any Linux devotees out there) but I do know that versions of mIRC newer than about a year or 2 at least are quite safe as long as you don't do dumb things like auto-accept everything and you don't run scripts from unknown sources ("Polaris" is a classical example of a script which many people use but not so many realize has a back door). In fact, the golden rule should really be don't run scripts at all - if you need a shortcut write it yourself. If you don't know enough about mIRC to do so and you use it enough to need something like that then perhaps its time to learn - its very very easy anyway. A DEFAULT installation of mIRC (no scripts, no tweaking of settings except for inputting details) is extremely safe, certainly more so than a default install of Outlook Express, as it warns you about anything and everything anyway and won't do things behind your back, the worst thing about it is that anyone on the same network can find out your IP address so if you really annoy them (or if they're up to no good) they can use that to mount an unrelated attack on your computer (but then that comes down to what other software you have on your computer). Note that such an attack can be mounted if they get your IP from a newsgroup post, an email or even a web based newsgroup - its not a problem specific to IRC. IMHO this is a small risk as NOT using IRC effectively becomes security by obscurity, not something that lasts very long with the number of people (or compromised machines) that just randomly scan for IPs to attack anyway and the number of places that record your IP address for public viewing. Even if you don't use IRC you should really take precautions like running an up-to-date virus scanner, don't enable sharing on your external interface, keep your installation well patched, run a personal firewall (www.zonelabs.com has a freeware one) and so on. These measures will also counter anything a malicious IRC user could do to you as well short of a flood attack (if you're on a dialup modem or if the adversary has an amplifying network), but that could happen with any medium anyway (for instance many web based newsgroups and newsgroups in general display your last known IP address as do some email services as anyone who's recieved a direct email from me would know). So thats my 2 cents ... just like anything else on the Internet, as long as you don't do dumb things, IRC is just as safe as any near-real-time communications channel on the Internet, except its considerably more real time than others. Don't let Tina frighten you from visiting #Libretto! - Raymond P.S. in case anyone is interested, in one of my many roles in life, I too am a security geek ... locking down computers such that they can withstand attacks from University level Computer Science students gets interesting ;-) --- /~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\ | | "Does fuzzy logic tickle?" | | ___ | "My HDD has no reverse. How do I backup?" | | /__/ +-------------------------------------------| | / \ a y b o t | [EMAIL PROTECTED] | | | HTTP://www.raybot.net | | ICQ: 31756092 | Need help? Visit #Windows98 on DALNet! | \~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~/ ************************************************************** http://libretto.basiclink.com - Libretto mailing list http://libretto.basiclink.com/archive - Archives http://www.picante.com/~gtaylor/portable/faq.html - FAQ -------TO UNSUBSCRIBE------- Reply to any of the list messages. The reply mail should be addressed to: [EMAIL PROTECTED] - Then replace any text on the message's subject line: cmd:unsubscribe --------TO UNSUBSCRIBE DIGEST------ Do above but with this on subject line: cmd:unsubscribe digest **************************************************************
