[dcc2] Re: dcc2 Digest, Vol 4, Issue 16

codemastr codemstr at ptd.net
Sun May 23 16:55:11 EDT 2004


> Re: Security concerns, don't forget to include notes about things such
> as DCCs to a channel, or CTCP replies to a channel.

Good point. Though I think the part about DCC belongs in the DCC draft, not
the CTCP draft.

Perhaps, in the CTCP draft, it is also worth mentioning that people will
often do a CTCP VERSION in order to determine if the user is vulnerable to
exploits? E.g. joining channels and looking for a mIRC 6.11 reply so you
know you can crash them with the DCC exploit.

Lastly, since Jesse mentioned that a CTCP could be ignored, perhaps it is
also worth mentioning that some IRC servers include a non-standard extension
to block all CTCPs sent to a channel and some even have it for CTCPs sent to
users.

-- codemastr




More information about the dcc2 mailing list