website/content/docs/security.md

2.7 KiB

Security & anti-abuse

echoIRCd's anti-abuse is a layered defence rather than a single engine, applied at the cheapest possible point in each case. (The behavioural DEFCON-style detection engine with a report-only mode lives in echo services, not in the daemon.)

The layers

  • Upstream / provider — volumetric floods (SYN/UDP/amplification) are handled before they reach the host.
  • Kernel / firewall — SYN cookies, per-IP connection-rate limits, conntrack caps.
  • echoIRCd — abusive sessions and content, described below.

Accept edge

Rejection before any per-connection state is allocated:

  • accept_rate / accept_burst — a per-source-IP token bucket, shared across the plaintext and TLS acceptors so one IP can't get a fresh budget per listener. Trusted proxies and server links are exempt.
  • connflood — refuse connections from an IP opening too many too fast.
  • connectban — Z-line an IP range that opens too many connections, with a boot grace period, garbage collection, and exemptions.

Per connection

  • Clone caps — connection classes cap concurrent per-IP connections (localmax, globalmax).
  • registration_timeout — drop connections that never send NICK+USER.
  • tls_handshake_timeout — reap sockets that open the TLS port but never negotiate.
  • conn_waitpong — hold registration until the client echoes an exact PING cookie.
  • recvq / softsendq / hardsendq — bound per-connection memory.

Per message

  • Fakelagflood_messages per flood_seconds throttles a fast client (opers exempt); a class may set fakelag=no to disconnect instead.
  • Channel modes +f (message flood), +j (join flood), +F (nick-change flood).

Screening & scoring

  • DNSBL — check DNS blocklists on connect; action mark / kill / kline / gline / zline.
  • Reputation — accrue a per-address score over time; surfaces the y: extban and WHOIS.
  • Security groups — named AND-ed user sets usable as the g: extban.

Content & behaviour

antirandom (drone nick/ident/realname scoring), antimixedutf8 (look-alike mixed-script spam), filter / badword (+G censor), solvemsg (arithmetic PM gate), recaptcha / cloudflare_challenge (registration gates), autodrop (HTTP-scanner connections), and blockamsg (mass /amsg). See Modules and the Configuration reference for the keys.

Network bans

Persistent K / G / Z / E (exempt) / Q (nick) / CBAN (channel) / SHUN / RLINE (realname) bans; TLINE <mask> reports how many current users a would-be ban would match before you set it.