Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Control channels with -n cause the bot to be vulnerable #350

Open
zuzak opened this issue Sep 5, 2019 · 0 comments
Open

Control channels with -n cause the bot to be vulnerable #350

zuzak opened this issue Sep 5, 2019 · 0 comments
Labels
bug problems that existing features cause difficult not easy

Comments

@zuzak
Copy link
Contributor

zuzak commented Sep 5, 2019

If the control channel is set to -n, any user can issue privileged commands to it without being on the channel. This means that any user could e.g. quit the bot without authentication.

The bot should either use a different authentication mechanism, or should refuse to execute privileged commands if the nick is not in channel. This could be done by keeping tracks of both nicknames and nickname changes in the control channel via the names event.

@zuzak zuzak added difficult not easy breaking RCE, DoS, or broken build on master branch bug problems that existing features cause and removed breaking RCE, DoS, or broken build on master branch labels Sep 5, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug problems that existing features cause difficult not easy
Projects
None yet
Development

No branches or pull requests

1 participant