RE: Whats up with this?
Patchou, i agree that changing someone elses nick isnt exactly 'dangerous', But all of the Messenger Plus! commands are available to these people to use - people wanted to find a way of getting an IP over messenger, now they have it.
However as timothy stated before: if someone has "/run application" in there name, typing (!N) will execute the run command (without the end user needing to type /run) and some people really are stupid enough to do this - believe me.
For example, if someone sets there name as "/nick ~~~(!IP)~~~~" its not so likley that the user (remember - not all messenger users are as smart as the people here) will recognise it as being malicious.
Is there not a way that you can filter out the (!N) command from executing any other commands, this would solve the problem.
Just my .02, you can choose what you want to do with Plus!, it is your extension after all. I just thaught that you may want to keep your users more secure from a potentially large security hole.
|