Author Archive

phpDenora fixes XSS vulnerability

Sunday, February 15th, 2009

After getting notified about a Cross-site scripting vulnerability in phpDenora irc-junkie quickly tried to get in touch with the project.

The vulnerability – which generally can be used to steal cookies – exists at least in phpDenoras then latest stable release, version 1.2.2 and “possibly all other versions” says developer Hal9000.

Due to lacking sanitization it was possible to exploit the vulnerability using specially crafted channelnames that would be visible on several pages of phpDenora – according to phpDenoras Hal9000 on the “channel listing, the channel stats page, the user stats page and the top channel list on the homepage – if the channel is in the top X channels”.

amnesiac: a script for EPIC5 – Interview

Sunday, February 15th, 2009

After interviewing the author of EPIC5, this sort of could be called a “follow-up” interview. The interviewees are the authors of amnesiac, a modular EPIC5 script.

- First, please introduce yourself to our readers so they get an idea who you are.

skullY: I’m a long-time UNIX user and administrator who works for a Silicon Valley startup.


My day job involves hating software (mainly Linux, Apache and MySQL) and I relax in the evenings by writing software to be hated.


Most of what I write is to scratch an itch, but a few things (amnesiac, nboard) see a wider release.

crapple(Zak): I’m a long-time UNIX user/admin/programmer working at a telecommunications company in Canada.

Anope switches their Support Network to InspIRCd

Monday, February 9th, 2009

Following the announcement of InspIRCd 1.2-rc1, the Anope project wrote a news article on their homepage, stating that they have switched IRCds on their support network.

They’re now using InspIRCd 1.2 and a development version from the new 1.9.0 series of their services package. Stating reasons for this move, away from stable to potentially unstable development versions of both programs, chaz says that they “chose InspIRCd as it’s a well maintained, highly motivated and definitely innovative product and we (Anope) should be the forefront of the technology for the sake of our users”.

InspIRCd releases 1.2rc1 “Sirloin”

Monday, February 9th, 2009

Today the InspIRCd project announced the availability of 1.2rc1 of their IRCd, named “Sirloin”.

Developer w00t writes in the newspost that “after a slightly longer development cycle than normal, we are proud as punch to announce that 1.2 has finally hit RC stage”. They consider this release “essentially feature-complete, and that relatively, the number of bugs is lower than in beta phase” but also note that “it’s not a final release yet, so you may still encounter some rough edges or bugs, we do ask that you report those to us on our bugtracker, so they may be addressed!”.

Mobile Colloquy review – version 1.0

Saturday, January 31st, 2009

Mobile Colloquy, the mobile counterpart of the popular Mac OS X IRC client, has hit Apples AppStore.

Even though this is the first release in its current form (there once was a version for jailbroken iPhones) and is only at version 1.0 right now, it already has quite a huge featurelist and a very polished UI. It’s built using the same framework, called Chat Core, as the desktop version.

The mobile version is opensource too, but unlike the desktop version – which is free – it costs $1.99 (€1.59). The sourcecode is freely available from SVN though, so you may build your own version – provided you do have Apples iPhone SDK.