OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: lifestages on IRC
From: T. H. Haymore (bonkWEBCHAT.CHATSYSTEMS.COM)
Date: Mon Jul 10 2000 - 10:27:59 CDT


On Sun, 9 Jul 2000, Omicron N wrote:

> hi
> I was on IRC ( on Win 2000) when i received a mesg window asking
> for permission to transfer the file LIFE_STAGES.TXT, I naturally said
> no. But when i saw the message in the Server connection window, the name
> was LIFE_STAGES.SHS. Now the threat from a virus/worm remains remote if
> the user is alert. But what i want to know is if it is possible to fool
> the user into clicking the wrong button and making him execute the file.

Assuming you were using mIRC, when one sends you something via DCC, their
real IP shows. I have never heard of that being 'spoofable'.

[11:16] -l33td00d- DCC Send lamer.txt (123.123.123.100) <--Ip of sending
machine/client.

It bothers me to see that you're being sent a file that indicates it's one
thing and it's really something else. Although the IP of the sender
shows, the real name of the file should show as well. Was it a ctcp
command you observed initially ? (ie /ctcp LIFE_STAGES.TXT) or a notice ?
Was it a GUI popup that displayed it ? If it's a txt file that's showing
as being sent and it's not, that's a problem the IRC Admins need to be
aware of to include the maker of the client.

>
> Is it possible to spoof the ip address given by the irc client to
> the IRC server ? Actually, i'm new to IRC and don't know anything about
> this. This "offer" of file happened twice , so i've started using irc on
> linux only. Also What can i do to track the guy who was doing me this
> "favor" ?
>

To find the user, find an IRC Operator to have them look for the user
provided you're on a network such as Undernet or DALNet that has IRCU to
support such a command. EFNet doesn't.

> Cheers
> Cheedu
>
>
> --
> *******
> Sridhar (cheedu) || mail: cheedugrex.org
> II Sem, || page: http://www.geocities.com/sri_dhar_n
> B.E Info Tech || site: cheedu.dyndns.org
> PESIT || nick: omicron,cheedu
>
> Smile.. Tomorrow will be worse
> --
>

================================================
Travis
AKA BONK
Email: BonkUndernet.Org | BonkWildstar.Net
================================================