mirror of
https://github.com/irssi/irssi.git
synced 2026-08-09 11:50:10 +02:00
The client of the future
https://irssi.org
- C 90.6%
- XS 3.4%
- Perl 2.1%
- Meson 2%
- Prolog 1.5%
- Other 0.4%
The server-first-message in SCRAM SASL authentication carries an i=<iteration_count> field that controls the PBKDF2 work factor. Previously irssi parsed this with strtoul and only rejected the zero case, then passed the value directly to PKCS5_PBKDF2_HMAC. Because the call is synchronous on the glib main loop and the 20-second SASL_TIMEOUT source is registered via g_timeout_add, a malicious server can send i=4294967295 (or larger) and deterministically hang irssi for the duration of the iteration count. Each reconnect attempt repeats the DoS. RFC 5802 section 5.1 explicitly allows a client to enforce a maximum iteration count. 100000 is well above any real-world server configuration (typically a few thousand) and bounds the worst-case PBKDF2 cost to a fraction of a second on modern hardware. |
||
|---|---|---|
| .github/workflows | ||
| .obs | ||
| docs | ||
| fuzz-support | ||
| scripts | ||
| src | ||
| subprojects | ||
| tests | ||
| themes | ||
| utils | ||
| .clang-format | ||
| .gitattributes | ||
| .gitignore | ||
| .muon_fmt.ini | ||
| AUTHORS | ||
| COPYING | ||
| INSTALL | ||
| irssi-icon.png | ||
| irssi.conf | ||
| MANIFEST.in | ||
| meson.build | ||
| meson_options.txt | ||
| NEWS | ||
| README.md | ||
| TODO | ||
Irssi
Irssi is a modular text mode chat client. It comes with IRC support built in, and there are third party ICB, SILC, XMPP (Jabber), PSYC and Quassel protocol modules available.
Download information
Development source installation
git clone https://github.com/irssi/irssi
cd irssi
meson Build
ninja -C Build && sudo ninja -C Build install
Release source installation
- Download release
- Verify signature
tar xJf irssi-*.tar.xz
cd irssi-*
meson Build
ninja -C Build && sudo ninja -C Build install
Requirements
- glib-2.32 or greater
- openssl
- perl-5.8 or greater (for perl support)
- terminfo or ncurses (for text frontend)
See the INSTALL file for details
Documentation
- New users guide
- Questions and Answers
- Check the built-in
/HELP, it has all the details on command syntax
Themes
Scripts
Modules
Security information
Please report security issues to staff@irssi.org. Thanks!
Bugs / Suggestions / Contributing
Check the GitHub issues if it is already listed in there; if not, open an issue on GitHub or send a mail to staff@irssi.org.
Irssi is always looking for developers. Feel free to submit patches through GitHub pull requests.
You can also contact the Irssi developers in #irssi on irc.libera.chat.
