[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <46F377FB.3010501@powersource.cx>
Date: Fri, 21 Sep 2007 09:51:23 +0200
From: Tom Laermans <tom.laermans@...ersource.cx>
To: IRC Security Discussion List <irc-security@...ts.irc-unity.org>
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: [irc-security] Multiple vulnerabilities in
ircu
Colin Alston wrote:
> Please be careful labeling something as "vulnerabilities" when they
> aren't. You've described software bugs which should be reported to the
> maintainer, none of them so far as I can see are vulnerabilities or
> exploits.
>
I can see crashbugs, operfloods, channel takeovers and ways to find out
people's IP addresses who think they are hidden thanks to the IP hiding
feature.
Having this malfunction certainly looks like a vulnerability to me.
Most vulnerabilities are indeed software bugs, and the exploits are
actually documented in the post you comment on.
Tom
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists