Firefox-based attack wreaks havoc on IRC users

Adam Bishop


While preventing firefox from connecting to IRC servers is one way to solve the problem, the question is "how?".

IRC connections are usually silent until the client sends a username and a nickname, and they have both been processed, making it next to impossible to detect if the server at the other end is an IRC server until everything has already been sent down the tube.

Port filtering is useless, as IRC servers can be run on any port.

This is more a vulnerability/issue in the IRC server implementation used on freenode, as it doesn't reject clients who send junk along when initialising the connection (the HTTP headers), and would be far, far easier to fix in the server.

After all, this isn't a firefox specific issue. Concievably, you could do this with anything that uses a TCP stream, from an IMAP client to, as the article said, SIP.

Samsung unwraps MacBook Air beater

Adam Bishop

Macbook Air Competitor?

At 30mm at its thickest point, that makes it thicker than my plain ol' macbook, at 27mm. If they really are trying to compete with the air, they're doing it wrong.

DRM in latest QuickTime cripples Adobe video editing code

Adam Bishop

*Not* DRM

Error -54 is a Unix Permissions errer, not a DRM error...

Cops seek 179mph net vid biker

Adam Bishop

@A. Boyer

Britain has been using miles since 55 BC, when the Romans invaded.

Harry Potter and the Virus of Doom

Adam Bishop


Wait, what?

Half of GPS users given duff information

Adam Bishop


You mean Sat Nav systems surely? How much damage can a stand-alone GPS do as it only gives out a grid reference?

Scientists uncover lefty gene

Adam Bishop


How many years of a cure for these unfortunate individuals are we?

Why is Hotmail so bad at spam?

Adam Bishop

You do know that

the hotmail spam filter is set to "low" by default... right?

Negroponte slams Intel over OLPC competition

Adam Bishop


I thought open source was about freedom of choice, competition, and diversity.

British Gas security scare as payments page springs a leak

Adam Bishop

Re: Direct Debit

Ah yes, the wonders of Direct debit, giving permission for them to take any amount of money they see fit to take, when they see fit to take it...

I'm sure I'm not the only one who has been sent quite deep into the red, due to a "billing error".

Space shuttle crashes in Alabama

Adam Bishop

Well that's a fantastic headline isn't it

Let is never be said that El Reg sensationalises stories...

'IE8 compatible' - the cure for web standards headache?

Adam Bishop

And just in case anyone needed any clarification...

2 years really is less than 3 years!