Bugtraq mailing list archives

psyBNC2.3 Beta - encrypted text spoofable in others irc terminal


From: psychoid () rewtbox de
Date: 22 Jan 2002 23:12:22 -0000

Subject: psyBNC2.3 Beta - encrypted text "spoofable" in others irc terminal

Hello,

thanks for reporting that problem.

I will solve this by appending a key checksum to the end of
each line. Example:

[B]text text text <1255>

The key checksum is part of the encrypted text. If it 
doesnt match for the user, he can be sure the text
is spoofed. Filtering special characters is no good
solution for that problem. It would need a 
full parse of every line entered, this would consume
too many resources.

The fix will be released soon.

Greetings,
psychoid


Current thread: