<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>IRC-Junkie.org - IRC News &#187; Unreal IRCd</title>
	<atom:link href="http://www.irc-junkie.org/tag/unreal-ircd/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.irc-junkie.org</link>
	<description>All about Internet Relay Chat</description>
	<lastBuildDate>Sun, 27 Nov 2011 23:50:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.irc-junkie.org/?pushpress=hub'/>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/de/</creativeCommons:license>		<item>
		<title>UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</title>
		<link>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/</link>
		<comments>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 19:46:45 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1266</guid>
		<description><![CDATA[UnrealIRCd, the IRCd that still dominates the usage statistics of all IRCds, has seen another stable release and is now at version 3.2.9.

After 2 release candidates and with 212 changes and bugfixes - almost the same amount as the last three stable releases combined - among which is a "substantial amount of new features" ...<p><a href="http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/">UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-02-05/inspircd-stable-1-2-3-released/' rel='bookmark' title='Permanent Link: InspIRCd stable 1.2.3 released'>InspIRCd stable 1.2.3 released</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>UnrealIRCd, the IRCd that still dominates the usage statistics of all IRCds, has seen another stable release and is now at version 3.2.9.</p>
<p>After 2 release candidates and with 212 changes and bugfixes &#8211; almost the same amount as the last three stable releases combined &#8211; among which is a <em>&#8220;substantial amount of new features&#8221;</em> as <em>Syzop</em> writes in their announcement.</p>
<p>He thanks everyone that made this release possible but especially mentions <em>binki</em> who did a <em>&#8220;considerable amount of work to make this release possible&#8221;.</em></p>
<p>And indeed, there is a large amount of changes &#8211; for example:</p>
<ul>
<li>Extended Bans (new modes introduced, ban stacking behaviour)</li>
<li>Extended Invite Exceptions / Invex</li>
<li>New Channelmode +Z which works in conjunction with +z (SSL only) and is set once every joined user is on SSL which might not be the case during netsplits/-joins</li>
<li>Remote MOTD support</li>
<li>Remote includes caching so that an old version of a remote include is loaded in case the webserver containing the include is down</li>
<li>/rehash -global &#8211; rehashes all servers at once</li>
<li>STARTTLS &#8211; connect to a &#8220;regular&#8221; port SSL encrypted</li>
<li>IPv6 clones detection support, defaults to /64</li>
</ul>
<p>A small excerpt of the bugs that have been fixed:</p>
<ul>
<li>Low connection frequencies (connfreq) no longer pose a problem due to reworking the corresponding code</li>
<li>IPv6 related fixes</li>
<li>an obscure crash bug that only occured rarely on outgoing connects</li>
</ul>
<p>Work on UnrealIRCd 3.3 already has begun and is, according to development plans, the replacement for the often retried and ultimately failed rewrite which was to be released as UnrealIRCd 4.</p>
<p>The release announcement can be found <a href="http://forums.unrealircd.com/viewtopic.php?t=7402">here</a> and the full changelog for changes since UnrealIRCd 3.2.8.1 is <a href="http://hg.unrealircd.com/hg/unreal/file/110ba58ecd56/Changes">here</a> (you need to scroll all the way down).</p>
<p><!--Digiprove_Start--><span lang="en" xml:lang="en" class="notranslate" style="vertical-align:middle; display:inline; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 9 November 2011 20:00:17 UTC by Digiprove certificate P198828" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P198828%26guid=p_WN-jrFEkCkmh2u1t6eig" target="_blank" rel="copyright" style="border:0px; float:none; display:inline; text-decoration: none; background-color:transparent"><img src="http://www.irc-junkie.org/wp-content/plugins/digiproveblog/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0" width="12px" height="12px" alt=""/><span style="font-family: Tahoma, MS Sans Serif; font-size:9px; font-weight:normal; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--A0A5617285E2A17892CA7DAA6ADF4F217B00A05BFAE91D37692B97705FD65CFF--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1266&amp;md5=2e08efc8a95149cbec4996f2b243f474" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/">UnrealIRCd 3.2.9 &#8211; New stable version after 2 years</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-02-05/inspircd-stable-1-2-3-released/' rel='bookmark' title='Permanent Link: InspIRCd stable 1.2.3 released'>InspIRCd stable 1.2.3 released</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2011-11-09/unrealircd-3-2-9-new-stable-version-after-2-years/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</title>
		<link>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/</link>
		<comments>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/#comments</comments>
		<pubDate>Sat, 12 Jun 2010 10:24:23 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=1034</guid>
		<description><![CDATA[Syzop of the UnrealIRCd project just posted an announcement on their mailinglist and forums that some versions of their IRCd have been compromised and had a backdoor added which went unnoticed for quite a while.

The first signs of the compromise have been traced back to November 2009 and Syzop writes that "Any Unreal3.2.8.1.tar.gz downloaded ...<p><a href="http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/">Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2007-05-13/syzop-resigns-his-position-on-the-unrealircd-project/' rel='bookmark' title='Permanent Link: Syzop resigns his position on the UnrealIRCd project'>Syzop resigns his position on the UnrealIRCd project</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2007-07-14/unrealircd-makes-a-drastic-change/' rel='bookmark' title='Permanent Link: UnrealIRCd Makes a Drastic Change'>UnrealIRCd Makes a Drastic Change</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><em>Syzop</em> of the UnrealIRCd project just posted an announcement on their mailinglist and forums that some versions of their IRCd have been compromised and had a backdoor added which went unnoticed for quite a while.</p>
<p>The first signs of the compromise have been traced back to November 2009 and <em>Syzop</em> writes that <em>&#8220;Any Unreal3.2.8.1.tar.gz downloaded BEFORE November 10 2009 should be  safe, but you should really double-check&#8221;</em>.</p>
<p><strong>Only the 3.2.8.1 source downloads (.tar.gz) are affected from this hack.</strong> Windows users, copies checked out from their CVS as well as users of older versions are safe and don&#8217;t need to check &#8211; everyone else should ensure they&#8217;re running a clean version of UnrealIRCd since the backdoor allows an attacker to issue and execute commands as the user the IRCd is running as, which essentially means your shell could easily compromised despite all other security measures.</p>
<p>Checking if your IRCd is one of those trojanized copies can easily be done either checking with md5sum or grep&#8217;ing the source for the backdoored code:</p>
<p>Run <em>&#8216;md5sum Unreal3.2.8.1.tar.gz&#8217;</em> on it and compare the resulting sum to the checksums below:<em> </em></p>
<blockquote><p>Backdoored version (BAD) is: 752e46f2d873c1679fa99de3f52a274d<br />
Official  version (GOOD) is: 7b741e94e867c0a7370553fd01506c66</p></blockquote>
<p>or use the command <em>&#8216;grep DEBUG3_DOLOG_SYSTEM include/struct.h&#8217;</em> from your Unreal3.2 directory &#8211; if this outputs 2 lines you&#8217;re running the trojanized version and need to get yourself a fresh and clean copy of the IRCd and recompile it since the compromised section is in the IRCds core and <em>&#8220;it is not possible to &#8216;clean&#8217; UnrealIRCd without a restart or through a  module&#8221;.</em></p>
<p><em>Syzop</em> writes that they have take precautions so such a compromise can never happen again and if it does that it&#8217;ll be noticed more quickly. They&#8217;re also planning to reimplement PGP/GPG signing of the releases which <em>&#8220;in practice (very) few people use&#8221;</em> but <em>&#8220;still [will] be useful for those people who do&#8221;</em>.</p>
<p>Closing his announcement he writes that he&#8217;d like to <em>&#8220;apologize about this security breach. We simply did not notice, but should have. We did not check the files  on all mirrors regularly, but should have. We did not sign releases  through PGP/GPG, but should have done so. Hope you&#8217;ll all continue to support UnrealIRCd&#8221;</em>.</p>
<p>The full announcement can be read <a href="http://forums.unrealircd.com/viewtopic.php?t=6562">here</a> and the advisory can be found <a href="http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt">here</a>.</p>
<p><strong>[Update]:</strong> Servers running the trojanized versions of UnrealIRCd should be updated as soon as possible since HD Moore, the creator of the Metasploit exploitation framework, already <a href="http://www.metasploit.com/redmine/projects/framework/repository/revisions/9503/entry/modules/exploits/unix/irc/unreal_ircd_3281_backdoor.rb">released a module for it</a> &#8211; but even without that the security hole is really simple to exploit.</p>
<p>Also, <a href="http://www.xzibition.com/fix-unreal.sh">here is a .sh script</a> that might help you in the upgrade process &#8211; at least one user on the UnrealIRCd forums claimed it worked for him (although no kind of guarantee is given neither by the author nor by me).</p>
<p><strong>[Update 2]:</strong> <em>Syzop</em> just <a href="http://forums.unrealircd.com/viewtopic.php?t=6563">posted a follow-up</a> in which he writes that their releases are <em>&#8220;from now on signed with GnuPG (PGP) again&#8221;</em>.</p>
<p><strong>[Update 3]:</strong> In an email to the UnrealIRCd mailinglist, <em>Syzop</em> elaborates on the GPG/PGP signing and says that there will be instructions on how to verify the key when you download the future releases. He also <a href="http://forums.unrealircd.com/viewtopic.php?f=1&amp;t=6566">goes into some detail which precautions the team has taken</a> that such an incident <em>&#8220;will never ever happen again&#8221;</em>. He rightfully criticizes certain news-outlets that claimed it was the fault of the Open Source model and even Linux (*cough*ZDNet*cough*) &#8211; some websites even confused the IRCd with EPIC softwares first-person shooter Unreal Tournament.</p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 14 June 2010 20:21:14 UTC by Digiprove certificate P20120" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P20120;guid=twt_eBsiyUesYmzK7R2MoQ" style="text-decoration:none" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0"/><span style="font-family: Tahoma, MS Sans Serif; font-size:11px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--7C9D003388986CD7761FB99CD0CE639CD8D75C1BB42607266C0B70A297CEE865--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=1034&amp;md5=deab499b17e98612f6ade2d4b0eef151" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/">Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2007-05-13/syzop-resigns-his-position-on-the-unrealircd-project/' rel='bookmark' title='Permanent Link: Syzop resigns his position on the UnrealIRCd project'>Syzop resigns his position on the UnrealIRCd project</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2007-07-14/unrealircd-makes-a-drastic-change/' rel='bookmark' title='Permanent Link: UnrealIRCd Makes a Drastic Change'>UnrealIRCd Makes a Drastic Change</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>UnrealIRCd team releases patch against Firefox XPS Attack</title>
		<link>http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/</link>
		<comments>http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 15:14:14 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=843</guid>
		<description><![CDATA[In a posting on the UnrealIRCd project website, coder Syzop announced a module that can help mitigate and completely stop the so-called "Firefox XPS Attack" (NSFW link).

The attack, which exploits the fact that malicious JavaScript can send arbitrary data to a wide range of ports, gained publicity when it was used against the freenode ...<p><a href="http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/">UnrealIRCd team releases patch against Firefox XPS Attack</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/' rel='bookmark' title='Permanent Link: Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]'>Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a></li>
<li><a href='http://www.irc-junkie.org/2005-09-23/xchat-author-warns-for-firefox-exploit/' rel='bookmark' title='Permanent Link: XChat Author Warns for Firefox Exploit'>XChat Author Warns for Firefox Exploit</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>In a posting on the <a href="http://forums.unrealircd.com/viewtopic.php?t=6458">UnrealIRCd project website</a>, coder <em>Syzop</em> announced a module that can help mitigate and completely stop the so-called &#8220;Firefox XPS Attack&#8221; (<a href="http://encyclopediadramatica.com/Firefox_XPS_IRC_Attack">NSFW link</a>).</p>
<p>The attack, which exploits the fact that malicious JavaScript can send arbitrary data to a wide range of ports, gained publicity when it was used against the freenode network over a period of a few weeks.</p>
<p>Even though the Mozilla project has a <a href="http://www.mozilla.org/projects/netlib/PortBanning.html#portlist">blocklist of ports</a> that are specifically not allowed to be communicated to, the port commonly used by IRC networks (6667) was not on those lists.</p>
<p>The attack &#8211; which ironically doesn&#8217;t affect Safari, Internet Explorer or Firefox with the NoScript extension &#8211; only works if the targeted IRC server does not use anti-spoofing measures before proceeding to the login phase.</p>
<p>UnrealIRCd generally is immune to the threat when it was compiled with the <em>NOSPOOF</em> feature which is enabled by default for the Windows builds but an option that <strong>defaults to &#8220;no&#8221; on Linux</strong> (<em>&#8220;Do you want to enable the server anti-spoof protection?&#8221;</em> &#8211; the first question on ./Config).</p>
<p>With the <a href="http://www.vulnscan.org/UnrealIRCd/modules/nopost.tar.gz">module</a> you can now instantly K/G/Z:Line such connections and therefore prevent them from filling up connection slots which might cause a DoS situation before they eventually time out. For maximum efficiency it is recommended you use both the module and the <em>NOSPOOF</em> option, however one works fine without the other.</p>
<p>To test whether your IRCd is vulnerable or the implemented measures against the attack are effective you can find the code that has been used against freenode <a href="http://encyclopediadramatica.com/Firefox_XPS_IRC_Attack#Example_source_.28click_plus_to_uncollapse.29">here</a>.</p>
<p>Thanks for the tip go to <em>katsklaw</em>!</p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=843&amp;md5=ad2ea136a6cbba3cb89f0e0787eb8f58" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/">UnrealIRCd team releases patch against Firefox XPS Attack</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-06-12/some-unrealircd-3-2-8-1-downloads-trojaned/' rel='bookmark' title='Permanent Link: Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]'>Some UnrealIRCd 3.2.8.1 downloads trojaned [Update 3]</a></li>
<li><a href='http://www.irc-junkie.org/2005-09-23/xchat-author-warns-for-firefox-exploit/' rel='bookmark' title='Permanent Link: XChat Author Warns for Firefox Exploit'>XChat Author Warns for Firefox Exploit</a></li>
<li><a href='http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/' rel='bookmark' title='Permanent Link: UnrealIRCd updates their IRCd to 3.2.8.1'>UnrealIRCd updates their IRCd to 3.2.8.1</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UnrealIRCd updates their IRCd to 3.2.8.1</title>
		<link>http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/</link>
		<comments>http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 13:54:56 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=620</guid>
		<description><![CDATA[The UnrealIRCd project released a bugfix release of version 3.2.8 and the current release is now 3.2.8.1.

The bugfix became necessary as a crash has been found in the option allow::options::noident.

In a short interview developer nate explains how the crash is being triggered and how to avoid it:
There was an issue in allow::options::noident, where if ...<p><a href="http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/">UnrealIRCd updates their IRCd to 3.2.8.1</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/' rel='bookmark' title='Permanent Link: UnrealIRCd team releases patch against Firefox XPS Attack'>UnrealIRCd team releases patch against Firefox XPS Attack</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-08/stskeeps-quits-developing-for-unrealircd/' rel='bookmark' title='Permanent Link: Stskeeps quits developing for UnrealIRCd'>Stskeeps quits developing for UnrealIRCd</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://unrealircd.com/">UnrealIRCd project</a> released a <a href="http://vulnscan.org/">bugfix</a> release of version 3.2.8 and the current release is now 3.2.8.1.</p>
<p>The bugfix became necessary as a <a href="http://forums.unrealircd.com/viewtopic.php?t=6172">crash has been found in the option <em>allow::options::noident</em></a>.</p>
<p>In a short interview developer <em>nate</em> explains how the crash is being triggered and how to avoid it:</p>
<blockquote><p>There was an issue in allow::options::noident, where if it was enabled in an allow block that a user could potentially crash a server due to a buffer overflow. As far as we&#8217;ve been able to see, there&#8217;s no risk of remote code execution as much as it just causing a segfault.  The main ways of resolving it are updating to 3.2.8.1 or simply making sure no allow blocks specifically have noident (which most by default won&#8217;t thankfully).</p>
<p>It is vulnerable in past versions as well before 3.2.8 as well.</p></blockquote>
<p>Being asked how far back exactly <em>nate</em> says the exploit exists <em>&#8220;at least back towards 3.2.3 (before that we wouldn&#8217;t support anyways due to exploits way back then)&#8221;</em>.</p>
<p>Thanks for the tip goes to <em>Reed Loden</em> and to <em>nate</em> for taking the time to answer my questions!</p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=620&amp;md5=b02a96105bca6a1273593ba0122c5f1e" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/">UnrealIRCd updates their IRCd to 3.2.8.1</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/' rel='bookmark' title='Permanent Link: UnrealIRCd 3.2.8-rc1 is ready for testing'>UnrealIRCd 3.2.8-rc1 is ready for testing</a></li>
<li><a href='http://www.irc-junkie.org/2010-03-01/unrealircd-team-releases-patch-against-firefox-xps-attack/' rel='bookmark' title='Permanent Link: UnrealIRCd team releases patch against Firefox XPS Attack'>UnrealIRCd team releases patch against Firefox XPS Attack</a></li>
<li><a href='http://www.irc-junkie.org/2008-12-08/stskeeps-quits-developing-for-unrealircd/' rel='bookmark' title='Permanent Link: Stskeeps quits developing for UnrealIRCd'>Stskeeps quits developing for UnrealIRCd</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2009-04-26/unrealircd-updates-their-ircd-to-3281/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unreal 3.2.8-rc2 has been released</title>
		<link>http://www.irc-junkie.org/2009-01-25/unreal-328-rc2-has-been-released/</link>
		<comments>http://www.irc-junkie.org/2009-01-25/unreal-328-rc2-has-been-released/#comments</comments>
		<pubDate>Sun, 25 Jan 2009 20:23:03 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[IRC]]></category>
		<category><![CDATA[IRCd]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Unreal IRCd]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=485</guid>
		<description><![CDATA[A little less than 4 weeks after the -rc1 release, there now is a -rc2 release of UnrealIRCd 3.2.8 available where some of the still present bugs have been fixed.

Fixes in this release include a bug that prevented you from compiling the IRCd on Mac OS X , problems with OperOverride that prevented you ...<p><a href="http://www.irc-junkie.org/2009-01-25/unreal-328-rc2-has-been-released/">Unreal 3.2.8-rc2 has been released</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-26/ngircd-version-13-released/' rel='bookmark' title='Permanent Link: ngIRCd version 13 released'>ngIRCd version 13 released</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-28/angrywolf-quits-unreal-module-development/' rel='bookmark' title='Permanent Link: AngryWolf quits Unreal Module development'>AngryWolf quits Unreal Module development</a></li>
<li><a href='http://www.irc-junkie.org/2010-01-25/new-ircd-ratbox-fixes-crashbugs/' rel='bookmark' title='Permanent Link: New ircd-ratbox stable release fixes crashbugs [Updated]'>New ircd-ratbox stable release fixes crashbugs [Updated]</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>A little less than 4 weeks after the <a href="http://www.irc-junkie.org/2008-12-29/unrealircd-328-rc1-is-ready-for-testing/">-rc1 release</a>, there now is a -rc2 release of UnrealIRCd 3.2.8 available where some of the still present bugs have been fixed.</p>
<p>Fixes in this release include a bug that prevented you from <a href="http://bugs.unrealircd.org/view.php?id=3767">compiling the IRCd on Mac OS X </a>, problems with OperOverride that <a href="http://bugs.unrealircd.org/view.php?id=3758">prevented you from -q/-a&#8217;ing</a> someone when you were halfop, an issue with <a href="http://bugs.unrealircd.org/view.php?id=3791">SuSE Linux 10.3 on AMD64</a> arch where the IRCd core-dumped on start, prevention of <a href="http://bugs.unrealircd.org/view.php?id=2521">throttling client connections</a> and <a href="http://bugs.unrealircd.org/view.php?id=3230">stalling the IRCd</a> when there are big adjustments made to the systems time after starting the IRCd and, last but not least, the <a href="http://www.vulnscan.org/UnrealIRCd/unreal32docs.html">documentation</a> has been <a href="http://bugs.unrealircd.org/view.php?id=3764">updated</a> to reflect the latest additions and changes.</p>
<p>The full announcement and changelog can be found <a href="http://forums.unrealircd.com/viewtopic.php?t=5942">here</a> and downloads are available from <a href="http://www.unrealircd.com/downloads.php">here</a>.</p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=485&amp;md5=17bc137ac3dc753925edd35e626186c3" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2009-01-25/unreal-328-rc2-has-been-released/">Unreal 3.2.8-rc2 has been released</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-12-26/ngircd-version-13-released/' rel='bookmark' title='Permanent Link: ngIRCd version 13 released'>ngIRCd version 13 released</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-28/angrywolf-quits-unreal-module-development/' rel='bookmark' title='Permanent Link: AngryWolf quits Unreal Module development'>AngryWolf quits Unreal Module development</a></li>
<li><a href='http://www.irc-junkie.org/2010-01-25/new-ircd-ratbox-fixes-crashbugs/' rel='bookmark' title='Permanent Link: New ircd-ratbox stable release fixes crashbugs [Updated]'>New ircd-ratbox stable release fixes crashbugs [Updated]</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2009-01-25/unreal-328-rc2-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

