home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!yale.edu!ira.uka.de!rz.uni-karlsruhe.de!s_titz
- From: s_titz@ira.uka.de (Olaf Titz)
- Newsgroups: alt.irc
- Subject: Re: /dcc
- Date: 21 Jan 1993 19:10:35 GMT
- Organization: Fachschaft math/inf, Uni Karlsruhe, FRG
- Lines: 36
- Message-ID: <1jmsfbINNe7o@nz12.rz.uni-karlsruhe.de>
- References: <1993Jan20.222051.1484@usage.csd.unsw.OZ.AU> <1993Jan21.120517.12904@aston.ac.uk>
- NNTP-Posting-Host: irau30.ira.uka.de
-
- In article <1993Jan21.120517.12904@aston.ac.uk> evansmp@uhura.aston.ac.uk (Mark Evans) writes:
-
- > How about having the recipient also be able to send a REFUSE CTCP back
- > which will cause the socket the requester is holding to be closed.
-
- Could be an idea, needs only to be implemented.
-
- > : Accept the connection.
- > could also put in a check that the host connecting to you is what you
- > expect it to be
-
- But how do you verify, no, how do you *know* what you expect it to be?
-
- > (while this is open anyone who knows it's port number can connect to it,
- > should be just the client you are trying to contact. Anyone who can run
- > a program such as netstat on your machine can find this out)
-
- Surely, there is a security hole. But I see no provision for fixing it
- while remaining compatible to the now existing thing.
-
- You could perhaps issue a WHOIS to find out the *host* of the other
- part, but not more. (Requesting the username too via an authentication
- server would throw out too many users, I suspect, and decreasing the
- chance that this protocol will be implemented in more client versions.)
-
- > Is a DCC REFUSE command currently included?
-
- You can DCC CLOSE the request, which will clean things up at your
- side, but not signal back to the requestor.
-
- Olaf
- --
- | Olaf Titz - comp.sc.student | o | uknf@dkauni2.bitnet | old address |
- | univ. of karlsruhe - germany | _>\ _ | s_titz@ira.uka.de | is still |
- | +49-721-60439 | (_)<(_) | praetorius@irc | valid |
- "My heart is human - my blood is boiling - my brain IBM" - Mr. Roboto
-