[IRCServices] /ns ghost exploit

Mark Hetherington mark at ctcp.net
Thu Mar 14 20:50:01 PST 2002


> Andrew Church wrote:
>      C'est la vie; I don't see this as a problem Services needs to handle.

I see. It is a problem Services introduced so it seemed appropriate for 
Services to handle it :( 

> If you have particular users doing this and it annoys other users, deal
> with the trouble causers individually.

Dealing with the current individuals concerned over this issue, does not 
make the problem go away. It merely creates a maintenance task each time 
someone new uses it. Prevention seems better than cure in this, as in any 
system.

It seems odd that I can turn off Services' own ability to kill users in 
various circumstances (NSForceNickChange), but must allow users the power 
to use Services to kill another user off the network, especially when 
Services is already "handling" the user depending on registration options. 
A single 'if (has_identified_nick())' (or similar) on the target would seem 
to be a suitable solution and is the one I will look into implementing. 

-- 
Mark.