Project

General

Profile

Bug #6347

Pidgin IRC Protocol responds to DCC SEND?

Added by Huiui almost 6 years ago. Updated 11 months ago.

Status:
Confirmed
Priority:
Low
Assignee:
-
Category:
-
Target version:
-
Start date:
10/08/2013
Due date:
% Done:

0%

Feature Branch:
Type of work:
Research
Blueprint:
Starter:
No
Affected tool:
Instant Messaging

Description

Lately it was discussed that pidgin answers to some CTCP requests (see https://labs.riseup.net/code/issues/5823). DCC (Direct client-to-client) should also be disabled, because it can leak to much identifying information. I'm not firm enough to understand the difference or how DCC interacts with CTCP (or if this is maybe already done), but i tried to send a DCC SEND request with XChat to another user with Tails/IRC. Even though the file transfer itself didn't work, he got a request to accept this file which means DCC isn't disabled at all. Maybe it's the firewall which is blocking here, but i am not sure how much information is leaking out. Please clarify this!


Related issues

Related to Tails - Feature #6117: Audit Pidgin Confirmed
Related to Tails - Bug #5823: Pidgin answers CTCP ping and version Rejected 09/19/2013
Related to Tails - Bug #8573: Hopefully replace Pidgin some day In Progress 01/07/2015

History

#1 Updated by mercedes508 almost 6 years ago

  • Status changed from New to Confirmed
  • Type of work changed from Discuss to Research

First should be to search for what kind of info Pidgin leaks trough DCC request. Then discuss if we care about those.

#2 Updated by BitingBird over 5 years ago

  • QA Check deleted (Info Needed)

#3 Updated by intrigeri almost 5 years ago

  • Category set to 213

#4 Updated by BitingBird over 4 years ago

#5 Updated by u 11 months ago

  • Related to Bug #5823: Pidgin answers CTCP ping and version added

#6 Updated by u 11 months ago

  • Priority changed from Normal to Low

#7 Updated by u 11 months ago

  • Related to Bug #8573: Hopefully replace Pidgin some day added

Also available in: Atom PDF