IRC and DCC send security risk

blaster blasterb@wanadoo.fr
Sun, 1 Jul 2001 09:03:08 +0200


Hi,

As mIRC now send 2 msg when you start a DCC (because it seems some irc
client need them both), netfilter should rewrite the ip in both and not only
in the PRIVMSG part because one of the NOTICE going out with your LAN ip
with is can be considered as a security risk giving out infos on the LAN
configuration.

There the 2 msg issues by mirc, see on DCC receiver side :

NOTICE nick :DCC Chat (myLANip)
PRIVMSG nick :DCC CHAT chat externalipinlongformat 1285

The myLANip should be rewrite too.