UnrealIRCd IP Cloaking Weakness Information Disclosure

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.


Synopsis :

The remote host appears to be running an IRC server.

Description :

The remote host is running UnrealIRCd, a popular IRC server.

The remote version of this server offers an 'IP cloaking'
capability that offers to hide the IP address of the users
connected to the server in order to preserve their anonymity.

There is a design error in the algorithm used by the server
that could allow an attacker to guess the real IP address of
another user of the server by reducing the number of tries to
2,000.

Solution :

Upgrade to UnrealIRCd 3.2.1

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.1
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 12297 ()

Bugtraq ID: 10663

CVE ID: CVE-2004-0679