<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>IRC-Junkie.org - IRC News &#187; Software</title>
	<atom:link href="http://www.irc-junkie.org/category/software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.irc-junkie.org</link>
	<description>All about Internet Relay Chat</description>
	<lastBuildDate>Sun, 27 Nov 2011 23:50:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.irc-junkie.org/?pushpress=hub'/>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/de/</creativeCommons:license>		<item>
		<title>IRC Defender arbitrary code execution exploit</title>
		<link>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/</link>
		<comments>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/#comments</comments>
		<pubDate>Sun, 27 Nov 2011 22:18:15 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Network Addons]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[IRC-Defender]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1274</guid>
		<description><![CDATA[Yesterday, news broke that there is an arbitrary code execution exploit within the still popular IRC security service IRC Defender which is, according to the reporter, being actively exploited.

The flaw is said to be within the InspIRCd link module for which a patched version exists, but according to the original post to the IRC-Security ...<p><a href="http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/">IRC Defender arbitrary code execution exploit</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-06-07/irc-defender-15-released/' rel='bookmark' title='Permanent Link: IRC Defender 1.5 Released'>IRC Defender 1.5 Released</a></li>
<li><a href='http://www.irc-junkie.org/2007-08-28/irc-defender-back-under-development/' rel='bookmark' title='Permanent Link: IRC Defender Back Under Development'>IRC Defender Back Under Development</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-09/ircu-family-ircd-dos-exploit/' rel='bookmark' title='Permanent Link: IRCu Family IRCd DoS Exploit'>IRCu Family IRCd DoS Exploit</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Yesterday, news broke that there is an arbitrary code execution exploit within the still popular IRC security service IRC Defender which is, according to the reporter, being actively exploited.</p>
<p>The flaw is said to be within the InspIRCd link module for which a patched version exists, but according to the original post to the IRC-Security mailinglist there are more flaws within the InspIRCd link module and also within the UnrealIRCd link module.</p>
<p>The original poster on the mailinglist suggests to get rid of IRC Defender immediately and to replace it with something else (have a look at <a href="http://www.omega-services.org/">Omega Security Services</a>) and also to check for signs of recent intrusions which have taken place on or after 15th November. He also urges to look out for rogue entries in ~/.ssh/authorized_keys and look for suspicious processes.</p>
<p>So far, at least three networks seem to have been exploited due to this flaw &#8211; the highest profile victim so far seems to be the <a href="http://seclists.org/fulldisclosure/2011/Nov/266">hack of the AnonOps network</a> which also seems to have been possible due to that flaw &#8211; contrary to the rumored Anope 0-day.</p>
<p>Original post on the IRC-Security mailinglist is <a href="http://lists.irc-unity.org/mailman/private/irc-security/2011-November/014558.html">here</a> (needs registration).</p>
<p>Thanks to <em>alyx</em> for the tip etc!</p>
<p>The patched inspircd12.pm link module can be obtained from <a href="http://www.irc-junkie.org/wp-content/uploads/inspircd12.pm">here</a>.</p>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 27 November 2011 23:50:31 UTC by Digiprove certificate P207845" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P207845%26guid=o5fVCR3EukWCyhZp9WExoA" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--53CE6565E25BE293C8114203F6A22133455498BA826C22A29385D20C8533EA18--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1274&amp;md5=6494fcaa30453dfee96887c9cd183d11" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/">IRC Defender arbitrary code execution exploit</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-06-07/irc-defender-15-released/' rel='bookmark' title='Permanent Link: IRC Defender 1.5 Released'>IRC Defender 1.5 Released</a></li>
<li><a href='http://www.irc-junkie.org/2007-08-28/irc-defender-back-under-development/' rel='bookmark' title='Permanent Link: IRC Defender Back Under Development'>IRC Defender Back Under Development</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-09/ircu-family-ircd-dos-exploit/' rel='bookmark' title='Permanent Link: IRCu Family IRCd DoS Exploit'>IRCu Family IRCd DoS Exploit</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-11-28/irc-defender-arbitrary-code-execution-exploit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</title>
		<link>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/</link>
		<comments>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 19:46:45 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1266</guid>
		<description><![CDATA[UnrealIRCd, the IRCd that still dominates the usage statistics of all IRCds, has seen another stable release and is now at version 3.2.9.

After 2 release candidates and with 212 changes and bugfixes - almost the same amount as the last three stable releases combined - among which is a "substantial amount of new features" ...<p><a href="http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/">UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-02-05/inspircd-stable-1-2-3-released/' rel='bookmark' title='Permanent Link: InspIRCd stable 1.2.3 released'>InspIRCd stable 1.2.3 released</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>UnrealIRCd, the IRCd that still dominates the usage statistics of all IRCds, has seen another stable release and is now at version 3.2.9.</p>
<p>After 2 release candidates and with 212 changes and bugfixes &#8211; almost the same amount as the last three stable releases combined &#8211; among which is a <em>&#8220;substantial amount of new features&#8221;</em> as <em>Syzop</em> writes in their announcement.</p>
<p>He thanks everyone that made this release possible but especially mentions <em>binki</em> who did a <em>&#8220;considerable amount of work to make this release possible&#8221;.</em></p>
<p>And indeed, there is a large amount of changes &#8211; for example:</p>
<ul>
<li>Extended Bans (new modes introduced, ban stacking behaviour)</li>
<li>Extended Invite Exceptions / Invex</li>
<li>New Channelmode +Z which works in conjunction with +z (SSL only) and is set once every joined user is on SSL which might not be the case during netsplits/-joins</li>
<li>Remote MOTD support</li>
<li>Remote includes caching so that an old version of a remote include is loaded in case the webserver containing the include is down</li>
<li>/rehash -global &#8211; rehashes all servers at once</li>
<li>STARTTLS &#8211; connect to a &#8220;regular&#8221; port SSL encrypted</li>
<li>IPv6 clones detection support, defaults to /64</li>
</ul>
<p>A small excerpt of the bugs that have been fixed:</p>
<ul>
<li>Low connection frequencies (connfreq) no longer pose a problem due to reworking the corresponding code</li>
<li>IPv6 related fixes</li>
<li>an obscure crash bug that only occured rarely on outgoing connects</li>
</ul>
<p>Work on UnrealIRCd 3.3 already has begun and is, according to development plans, the replacement for the often retried and ultimately failed rewrite which was to be released as UnrealIRCd 4.</p>
<p>The release announcement can be found <a href="http://forums.unrealircd.com/viewtopic.php?t=7402">here</a> and the full changelog for changes since UnrealIRCd 3.2.8.1 is <a href="http://hg.unrealircd.com/hg/unreal/file/110ba58ecd56/Changes">here</a> (you need to scroll all the way down).</p>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 9 November 2011 20:00:17 UTC by Digiprove certificate P198828" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P198828%26guid=p_WN-jrFEkCkmh2u1t6eig" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--A0A5617285E2A17892CA7DAA6ADF4F217B00A05BFAE91D37692B97705FD65CFF--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1266&amp;md5=2e08efc8a95149cbec4996f2b243f474" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/">UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-02-05/inspircd-stable-1-2-3-released/' rel='bookmark' title='Permanent Link: InspIRCd stable 1.2.3 released'>InspIRCd stable 1.2.3 released</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hybrid releases 7.3.0</title>
		<link>http://www.irc-junkie.org/2011-08-14/hybrid-releases-7-3-0/</link>
		<comments>http://www.irc-junkie.org/2011-08-14/hybrid-releases-7-3-0/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 10:05:18 +0000</pubDate>
		<dc:creator>Kottizen</dc:creator>
				<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Hybrid]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1255</guid>
		<description><![CDATA[

Earlier this week, Jon Lusky released a new version of ircd-hybrid. The version number has now reached 7.3.0. Among the changes you find a new Bulgarian translation, a fixed IPv6 implementation and channel modes O and S for opers-only respective SSL/TLS-only clients. Server administrators now get to choose whether they want to use SSLv3 ...<p><a href="http://www.irc-junkie.org/2011-08-14/hybrid-releases-7-3-0/">Hybrid releases 7.3.0</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-01-05/ircd-hybrid-derivate-esphyb-releases-version-1-0-4/' rel='bookmark' title='Permanent Link: IRCd-Hybrid derivate &#8220;esphyb&#8221; releases version 1.0.4 [Updated]'>IRCd-Hybrid derivate &#8220;esphyb&#8221; releases version 1.0.4 [Updated]</a></li>
<li><a href='http://www.irc-junkie.org/2009-03-11/inspircd-releases-120rc2-peppersteik/' rel='bookmark' title='Permanent Link: InspIRCd releases 1.2.0rc2 &#8220;PepperSteik&#8221;'>InspIRCd releases 1.2.0rc2 &#8220;PepperSteik&#8221;</a></li>
<li><a href='http://www.irc-junkie.org/2009-01-01/anope-releases-180-stable-of-their-irc-services-package/' rel='bookmark' title='Permanent Link: Anope releases 1.8.0-stable of their IRC services package'>Anope releases 1.8.0-stable of their IRC services package</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div>
<p>Earlier this week, Jon Lusky <a href="http://lists.ircd-hybrid.org/pipermail/hybrid/2011-August/001364.html">released a new version of ircd-hybrid</a>. The version number has now reached 7.3.0. Among the changes you find a new Bulgarian translation, a fixed IPv6 implementation and channel modes O and S for opers-only respective SSL/TLS-only clients. Server administrators now get to choose whether they want to use SSLv3 or TLSv1 to secure connections. All spy-notice modules that previously covered reports for usage of STATS, TRACE, MOTD and ADMIN have been replaced by server-sided notices. The old LazyLinks concept has now been removed, as it was half broken. The WATCH command known from UnrealIRCd and Bahamut has been added. In addition to that, a few minor cleanups and bugs leading to crashes have been fixed.</p>
<p>Hybrid is used together with Ratbox (which is a fork) and CSIRCd on both EFnet and IRCsource. It has been forked many times and it&#8217;s known for its stability and quality of code.</p>
<p>By looking at the SVN repository it seems like the developer team behind Hybrid <a href="http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid-8/">is working towards a 8.0 release</a>, featuring better services support while still keeping simplicity.</p>
</div>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 14 August 2011 10:05:18 UTC by Digiprove certificate P164581" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P164581%26guid=TWBWQ3QvbkmnCb2EDNgKxw" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--ED263268C8115744403CA8D452CACE26D1C479785EF9F4C4A6ABACCA9445EA73--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1255&amp;md5=136f7a3a0af8c6088326db7dd7e776dd" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-08-14/hybrid-releases-7-3-0/">Hybrid releases 7.3.0</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-01-05/ircd-hybrid-derivate-esphyb-releases-version-1-0-4/' rel='bookmark' title='Permanent Link: IRCd-Hybrid derivate &#8220;esphyb&#8221; releases version 1.0.4 [Updated]'>IRCd-Hybrid derivate &#8220;esphyb&#8221; releases version 1.0.4 [Updated]</a></li>
<li><a href='http://www.irc-junkie.org/2009-03-11/inspircd-releases-120rc2-peppersteik/' rel='bookmark' title='Permanent Link: InspIRCd releases 1.2.0rc2 &#8220;PepperSteik&#8221;'>InspIRCd releases 1.2.0rc2 &#8220;PepperSteik&#8221;</a></li>
<li><a href='http://www.irc-junkie.org/2009-01-01/anope-releases-180-stable-of-their-irc-services-package/' rel='bookmark' title='Permanent Link: Anope releases 1.8.0-stable of their IRC services package'>Anope releases 1.8.0-stable of their IRC services package</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-08-14/hybrid-releases-7-3-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ii &#8211; A Filesystem-based IRC Client</title>
		<link>http://www.irc-junkie.org/2010-09-13/ii-a-filesystem-based-irc-client/</link>
		<comments>http://www.irc-junkie.org/2010-09-13/ii-a-filesystem-based-irc-client/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 16:22:36 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Clients]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ii]]></category>
		<category><![CDATA[IRC IT]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1230</guid>
		<description><![CDATA[There are many different IRC clients out there and no matter what your preferences are, you're almost guaranteed to find one that will suit your needs.

Most clients today provide some sort of graphical user interface or come with an ASCII-based interface. And while the latter, CLI-based clients, are commonly thought to be the most ...<p><a href="http://www.irc-junkie.org/2010-09-13/ii-a-filesystem-based-irc-client/">ii &#8211; A Filesystem-based IRC Client</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-02-12/kde-irc-client-konversation-releases-version-1-2-3/' rel='bookmark' title='Permanent Link: KDE IRC client Konversation releases version 1.2.3'>KDE IRC client Konversation releases version 1.2.3</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-14/yaaic-yet-another-android-irc-client-0-1-beta-released/' rel='bookmark' title='Permanent Link: Yaaic &#8211; Yet another Android IRC client 0.1 Beta released'>Yaaic &#8211; Yet another Android IRC client 0.1 Beta released</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-18/irc-client-nettalk-6-7-4-released/' rel='bookmark' title='Permanent Link: IRC client Nettalk 6.7.4 released'>IRC client Nettalk 6.7.4 released</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>There are many different IRC clients out there and no matter what your preferences are, you&#8217;re almost guaranteed to find one that will suit your needs.</p>
<p>Most clients today provide some sort of graphical user interface or come with an ASCII-based interface. And while the latter, CLI-based clients, are commonly thought to be the most basic variant of an IRC client, i was surprised to find a client that manages to be even more plain: <em>ii</em> or <em>IRC IT.</em></p>
<p><em>ii</em> is a <em>&#8220;minimalist FIFO and filesystem-based IRC client&#8221;</em>, meaning every channel, private message and other server communication is represented by a directory containing an <em>in</em> and an <em>out</em> file.</p>
<p>Even though its sourcecode is just under 500 lines, it supports the most  basic commands like joining and parting, changing nickname and setting  topics. All other commands currently not understood by <em>ii</em> can be written as per the RFC and will get sent directly to the server then.</p>
<p>Using standard Linux/Unix commandline-tools like <em>echo</em>, <em>cat</em>, <em>tail</em> and <em>grep</em> you can control <em>IRC IT</em> which almost behaves like a normal IRC client then.</p>
<p>Join a channel? Sure, just <em>echo &#8220;/j #yourchannelname&#8221; &gt; servernamedir/in</em> and you&#8217;ll join that channel, creating an <em>out</em> file you can monitor with <em>tail -f</em>.</p>
<div id="attachment_1233" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.irc-junkie.org/wp-content/uploads/ii_channelview.jpg"><img class="size-medium wp-image-1233" title="ii Channelview" src="http://www.irc-junkie.org/wp-content/uploads/ii_channelview-300x52.jpg" alt="ii Channelview" width="300" height="52" /></a><p class="wp-caption-text">ii Channelview</p></div>
<p>After a little while, your directory structure will look like this:</p>
<div id="attachment_1234" class="wp-caption aligncenter" style="width: 190px"><a href="http://www.irc-junkie.org/wp-content/uploads/ii_treeview.jpg"><img class="size-full wp-image-1234" title="ii Treeview" src="http://www.irc-junkie.org/wp-content/uploads/ii_treeview.jpg" alt="ii Treeview" width="180" height="319" /></a><p class="wp-caption-text">ii Treeview</p></div>
<p>Users of the <em>vim</em> editor who always looked envious at the <em>Emacs</em> editor because of its built-in IRC client <a href="http://savannah.gnu.org/projects/erc/"><em>ERC</em></a> &#8211; fret not: <a href="http://nion.modprobe.de/blog/archives/440-Using-the-ii-irc-client.html">This blog-post</a> details how to configure <em>vim</em> to be used as an IRC client in combination with <em>ii</em>.</p>
<p>So if you feel like trying something new, grab <em>ii</em> from <a href="http://tools.suckless.org/ii/">here</a> and after a fast and hassle-free compiler-run you&#8217;re up and running &#8211; Who knows, maybe you&#8217;ve got a favourite new IRC client?</p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 13 September 2010 16:22:37 UTC by Digiprove certificate P46303" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P46303;guid=Pim3NAgrCUibCwT4Nr4qgw" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--5008442A3B84E0DFD8CE7691FCFCD74EC816F33D1932D2ACE28D9ABB67D8F440--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1230&amp;md5=f4fec7f3493cc3b1571f7acb0048280b" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-09-13/ii-a-filesystem-based-irc-client/">ii &#8211; A Filesystem-based IRC Client</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-02-12/kde-irc-client-konversation-releases-version-1-2-3/' rel='bookmark' title='Permanent Link: KDE IRC client Konversation releases version 1.2.3'>KDE IRC client Konversation releases version 1.2.3</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-14/yaaic-yet-another-android-irc-client-0-1-beta-released/' rel='bookmark' title='Permanent Link: Yaaic &#8211; Yet another Android IRC client 0.1 Beta released'>Yaaic &#8211; Yet another Android IRC client 0.1 Beta released</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-18/irc-client-nettalk-6-7-4-released/' rel='bookmark' title='Permanent Link: IRC client Nettalk 6.7.4 released'>IRC client Nettalk 6.7.4 released</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-09-13/ii-a-filesystem-based-irc-client/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>KVIrc 3.x and 4.x Remote Command Execution Vulnerability</title>
		<link>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/</link>
		<comments>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/#comments</comments>
		<pubDate>Sun, 01 Aug 2010 15:03:19 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Clients]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[KVIrc]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1194</guid>
		<description><![CDATA[All current versions of the KVIrc IRC client contain a remotely exploitable command execution vulnerability, including builds of KVIrc 4 from subversion up to revision 4692 as well as the older 3.x versions.

The bug, triggered by inserting carriage returns (r) into DCC GET commands, can be used to execute every command the IRCd understands ...<p><a href="http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/">KVIrc 3.x and 4.x Remote Command Execution Vulnerability</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-10-31/kvirc-340-irc-uri-handler-format-string-vulnerability-reloaded/' rel='bookmark' title='Permanent Link: KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded'>KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-12/bnc-289-remote-buffer-overflow/' rel='bookmark' title='Permanent Link: BNC 2.8.9 remote buffer overflow'>BNC 2.8.9 remote buffer overflow</a></li>
<li><a href='http://www.irc-junkie.org/2008-11-22/kvirc-342-uri-handler-in-combination-with-ie-exploitable/' rel='bookmark' title='Permanent Link: KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]'>KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>All current versions of the KVIrc IRC client contain a remotely exploitable command execution vulnerability, including builds of KVIrc 4 from subversion up to revision 4692 as well as the older 3.x versions.</p>
<p>The bug, triggered by inserting carriage returns (r) into DCC GET commands, can be used to execute every command the IRCd understands in the context of the user running the vulnerable client instance.</p>
<p>To check if your version is exploitable you can either take a look at the &#8220;About KVIrc&#8221; tab under &#8220;Help&#8221; and check the revision or execute the following command on IRC:</p>
<blockquote><p>/echo $version</p></blockquote>
<p>To make matters worse, whole channels can be exploited at once if they don&#8217;t have a mode set that disallows CTCPing them.</p>
<p>A quick workaround is to execute the following command, effectively preventing those &#8220;failed&#8221; DCC handshakes to be notified and disabling the bug:</p>
<blockquote><p>/option boolNotifyFailedDccHandshakes 0</p></blockquote>
<p>To see if you&#8217;ve already been exploited you can take a look in your server window and search for lines that look similar to these:</p>
<blockquote><p>[01:27:46] Processing DCC GET PRIVMSG #kvirc :I&#8217;m owned<br />
request from ATTACKER [ATTACKER@HOSTNAME] (DCC GETrPRIVMSG40#kvirc40:I&#8217;m40ownedr)<br />
[01:27:46] Unable to process the above request: Unknown DCC type &#8216;GET PRIVMSG #KVIRC :I&#8217;M OWNED &#8216;, Ignoring and notifying failure</p></blockquote>
<p>Updated builds of KVIrc are <a href="http://kvirc.net/?id=releases">available on their homepage</a> &#8211; some distributions also already have updated builds in their repository. If you can&#8217;t update because your distribution is not among the one with updated builds, the workaround helps to not fall prey to any possible attackers.</p>
<p><a href="https://svn.kvirc.de/kvirc/ticket/858">Original report on KVIrc bugtracker</a><br />
<a href="http://secunia.com/advisories/40727">Advisory on Secunia.com</a></p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 6 August 2010 18:11:18 UTC by Digiprove certificate P37679" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P37679;guid=CDJ3ZzZugEivFqyFMFSPLg" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--C5C934ECB28D4A7B4E495E8EB05A83B14E95196A9A9321F15C57DDF192029279--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1194&amp;md5=bc63ad3a9ca312d1fadfe6b4be21f40b" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/">KVIrc 3.x and 4.x Remote Command Execution Vulnerability</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-10-31/kvirc-340-irc-uri-handler-format-string-vulnerability-reloaded/' rel='bookmark' title='Permanent Link: KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded'>KVIrc 3.4.0 irc:// URI handler format string vulnerability &#8211; reloaded</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-12/bnc-289-remote-buffer-overflow/' rel='bookmark' title='Permanent Link: BNC 2.8.9 remote buffer overflow'>BNC 2.8.9 remote buffer overflow</a></li>
<li><a href='http://www.irc-junkie.org/2008-11-22/kvirc-342-uri-handler-in-combination-with-ie-exploitable/' rel='bookmark' title='Permanent Link: KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]'>KVIrc 3.4.2 URI handler in combination with IE exploitable [Updated]</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-08-01/kvirc-3-x-and-4-x-remote-command-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

