Re: [Full-disclosure] [irc-security] Multiple vulnerabilities in ircu

2007-09-21 Thread Colin Alston
Please be careful labeling something as vulnerabilities when they 
aren't. You've described software bugs which should be reported to the 
maintainer, none of them so far as I can see are vulnerabilities or 
exploits.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] [irc-security] Multiple vulnerabilities in ircu

2007-09-21 Thread Tom Laermans
Colin Alston wrote:
 Please be careful labeling something as vulnerabilities when they 
 aren't. You've described software bugs which should be reported to the 
 maintainer, none of them so far as I can see are vulnerabilities or 
 exploits.
   
I can see crashbugs, operfloods, channel takeovers and ways to find out 
people's IP addresses who think they are hidden thanks to the IP hiding 
feature.
Having this malfunction certainly looks like a vulnerability to me.

Most vulnerabilities are indeed software bugs, and the exploits are 
actually documented in the post you comment on.

Tom

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/