• Re: :)

    From Dmitry Protasoff@2:5001/100 to Karel Kral on Mon Sep 7 02:57:16 2026
    Hello Karel!

    In a message of 28 Jul 26 08:41, Karel wrote to Dmitry:

    One another idea: start stats related to PING. It would need more
    than just connect (e.g. send netmail, receive netmail, process
    netmail). E.g. is PING working (yes, no, +latency). Maybe more:
    send it routed and dig Via lines? (and create topology).

    I'm actually doing this test right now and here's what I see:

    1. TRACE is often unsupported, despite announcement.
    2. Some nodes send replies via direct insecure links.
    3. The amount of hate from Nick Andre I've received was enormous ;) Sounds like he is just mentally sick person.

    See you,
    dp.
    --- FidoMail v0.1.4-25-g6af97be
    * Origin: livin' on the edge (2:5001/100)
  • From Michiel van der Vlist@2:280/5555 to Dmitry Protasoff on Mon Sep 7 10:30:36 2026
    Hello Dmitry,

    On 07 Sep 26 02:57, you wrote to Karel Kral:

    One another idea: start stats related to PING. It would need more
    than just connect (e.g. send netmail, receive netmail, process
    netmail). E.g. is PING working (yes, no, +latency). Maybe more:
    send it routed and dig Via lines? (and create topology).

    I'm actually doing this test right now and here's what I see:

    1. TRACE is often unsupported, despite announcement.

    That doesn't really surprise me.

    2. Some nodes send replies via direct insecure links.

    I see no problem in that.

    3. The amount of hate from Nick Andre I've received was enormous ;)
    Sounds like he is just mentally sick person.

    That does not surprise me either. Just ignore him.

    Keep up the good work!


    Cheers, Michiel

    --- GoldED+/W32-MINGW 1.1.5-b20260904
    * Origin: http://www.vlist.eu (2:280/5555)
  • From Karel Kral@2:423/39 to Dmitry Protasoff on Mon Sep 7 12:37:10 2026
    Hello Dmitry!

    07 Sep 26 02:57, you wrote to me:

    I'm actually doing this test right now and here's what I see:

    1. TRACE is often unsupported, despite announcement.
    2. Some nodes send replies via direct insecure links.
    3. The amount of hate from Nick Andre I've received was enormous ;)

    It is generating some extra traffic - but everybody should be happy to get it tested ;-)

    In my case - looks like so far - I was not ready to get more than one PING at same time (still investigating).

    Thank you for your work

    Karel

    --- GoldED+/LNX 1.1.5-b20240209
    * Origin: Plast DATA (2:423/39)
  • From Tommi Koivula@2:221/1.22 to Dmitry Protasoff on Mon Sep 7 14:57:06 2026
    In a message of 07 Sep 26 02:57, Dmitry wrote to Karel:

    2. Some nodes send replies via direct insecure links.

    This is the most secure way to send netmail. :)

    'Tommi


    --- FidoMail v0.1.4
    * Origin: fidomail @ mxt.fidonet.fi (2:221/1.22)
  • From Alexey Fayans@2:5030/1997 to Tommi Koivula on Mon Sep 7 15:08:51 2026
    Hello Tommi!

    On Mon, 07 Sep 2026 14:57 +0300, you wrote to Dmitry Protasoff:

    2. Some nodes send replies via direct insecure links.
    This is the most secure way to send netmail. :)

    I can send such netmail on your behalf and recipient will not even suspect it wasn't from you.


    ... Music Station BBS | https://bbs.bsrealm.net | telnet://bbs.bsrealm.net
    --- GoldED+/W32-MSVC 1.1.5-b20180707
    * Origin: Music Station | https://ms.bsrealm.net (2:5030/1997)
  • From Michiel van der Vlist@2:280/5555 to Alexey Fayans on Mon Sep 7 14:30:53 2026
    Hello Alexey,

    On 07 Sep 26 15:08, you wrote to Tommi Koivula:

    2. Some nodes send replies via direct insecure links.

    This is the most secure way to send netmail. :)

    I can send such netmail on your behalf and recipient will not even
    suspect it wasn't from you.

    So tell me, what is to be gained by doing this with a PING response?


    Cheers, Michiel

    --- GoldED+/W32-MINGW 1.1.5-b20260904
    * Origin: http://www.vlist.eu (2:280/5555)
  • From Dmitry Protasoff@2:5001/100 to Michiel van der Vlist on Mon Sep 7 13:00:22 2026
    Hello Michiel!

    In a message of 07 Sep 26 10:30, Michiel wrote to Dmitry:

    MvdV> That does not surprise me either. Just ignore him.

    MvdV> Keep up the good work!

    Thank you!

    The report is here: https://nodelist.fidonet.cc/analytics/pingtrace
    Any comments, ideas, etc - are always welcome!

    Now I need to add TRACE/PING flags to my own nodes and test myself too :)

    See you,
    dp.
    --- FidoMail v0.1.4-26-gc93e772
    * Origin: livin' on the edge (2:5001/100)
  • From Alexey Fayans@2:5030/1997 to Michiel van der Vlist on Mon Sep 7 15:58:33 2026
    Hello Michiel!

    On Mon, 07 Sep 2026 14:30 +0200, you wrote to me:

    This is the most secure way to send netmail. :)
    I can send such netmail on your behalf and recipient will not
    even suspect it wasn't from you.
    So tell me, what is to be gained by doing this with a PING response?

    I just commented on "the most secure way to send netmail". Still, if I wanted to spam someone with responses to PING, I could use such "vulnerability".


    ... Music Station BBS | https://bbs.bsrealm.net | telnet://bbs.bsrealm.net
    --- GoldED+/W32-MSVC 1.1.5-b20180707
    * Origin: Music Station | https://ms.bsrealm.net (2:5030/1997)
  • From Dmitry Protasoff@2:5001/100 to Karel Kral on Mon Sep 7 13:06:21 2026
    Hello Karel!

    In a message of 07 Sep 26 12:37, Karel wrote to Dmitry:

    In my case - looks like so far - I was not ready to get more than
    one PING at same time (still investigating).

    The report is here: https://nodelist.fidonet.cc/analytics/pingtrace
    The colour of PING icons will change after 7 days without an answer.

    Thank you for your work

    Thanks!! And thank you for the report idea.


    See you,
    dp.
    --- FidoMail v0.1.4-26-gc93e772
    * Origin: livin' on the edge (2:5001/100)
  • From Yegor Gluhov@2:382/736 to Michiel van der Vlist on Mon Sep 7 15:09:08 2026
    Hello Michiel!

    07 Sep 26 14:30, you wrote to Alexey Fayans:

    2. Some nodes send replies via direct insecure links.
    This is the most secure way to send netmail. :)
    I can send such netmail on your behalf and recipient will not even
    suspect it wasn't from you.
    So tell me, what is to be gained by doing this with a PING response?

    With a PING response, probably, nothing. How about a PING request from a spoofed sender? FTS-4010 doesn't distinguish between secure and insecure links.

    Yegor
    --- AmberEdit/linux 0.7.1
    * Origin: to err is human, but to really f.. things up you need AI (2:382/736)
  • From Dmitry Protasoff@2:5001/100 to Tommi Koivula on Mon Sep 7 13:14:27 2026
    Hello Tommi!

    In a message of 07 Sep 26 14:57, Tommi wrote to Dmitry:

    2. Some nodes send replies via direct insecure links.

    This is the most secure way to send netmail. :)

    Well, can't argue with that :)


    See you,
    dp.
    --- FidoMail v0.1.4-26-gc93e772
    * Origin: livin' on the edge (2:5001/100)
  • From Dmitry Protasoff@2:5001/100 to Yegor Gluhov on Mon Sep 7 13:34:06 2026
    Hello Yegor!

    In a message of 07 Sep 26 15:09, Yegor wrote to Michiel:

    With a PING response, probably, nothing.

    I use MSGID to match replies.


    See you,
    dp.
    --- FidoMail v0.1.4-26-gc93e772
    * Origin: livin' on the edge (2:5001/100)
  • From Michiel van der Vlist@2:280/5555 to Alexey Fayans on Mon Sep 7 15:22:21 2026
    Hello Alexey,

    On 07 Sep 26 15:58, you wrote to me:


    Still, if I wanted to spam someone with responses to PING, I could use such "vulnerability".

    And the gain of such an action would be?


    Cheers, Michiel

    --- GoldED+/W32-MINGW 1.1.5-b20260904
    * Origin: http://www.vlist.eu (2:280/5555)
  • From Michiel van der Vlist@2:280/5555 to Yegor Gluhov on Mon Sep 7 15:24:22 2026
    Hello Yegor,

    On 07 Sep 26 15:09, you wrote to me:

    So tell me, what is to be gained by doing this with a PING
    response?

    How about a PING request from a spoofed sender?

    And the gain of such an action would be?

    FTS-4010 doesn't distinguish between secure and insecure links.

    If you are worried about problems with spoofed ping requests coming in via an unsecure link, just don't fly the PING flag. Simple!


    Cheers, Michiel

    --- GoldED+/W32-MINGW 1.1.5-b20260904
    * Origin: http://www.vlist.eu (2:280/5555)
  • From Alexey Fayans@2:5030/1997 to Yegor Gluhov on Mon Sep 7 16:44:56 2026
    Hello Yegor!

    On Mon, 07 Sep 2026 15:09 +0200, you wrote to Michiel van der Vlist:

    @MSGID: 2:382/736 6a9eb774
    @TZUTC: 0200
    @CHRS: LATIN-1 2
    [...]
    --- AmberEdit/linux 0.7.1

    Doesn't it support REPLY kludge?


    ... Music Station BBS | https://bbs.bsrealm.net | telnet://bbs.bsrealm.net
    --- GoldED+/W32-MSVC 1.1.5-b20180707
    * Origin: Music Station | https://ms.bsrealm.net (2:5030/1997)
  • From Alexey Fayans@2:5030/1997 to Michiel van der Vlist on Mon Sep 7 16:57:31 2026
    Hello Michiel!

    On Mon, 07 Sep 2026 15:22 +0200, you wrote to me:

    Still, if I wanted to spam someone with responses to PING, I
    could use such "vulnerability".
    And the gain of such an action would be?

    Would you ask the same question to a security audit of your company network infrastructure or something like that?

    - You are running an outdated kernel, this is a list of exploitable vulnerabilities.
    - And the gain of exploiting any of them would be?

    Someone may want to do that just because they can. If there is an exploitable vulnerability, it will be exploited some day.


    ... Music Station BBS | https://bbs.bsrealm.net | telnet://bbs.bsrealm.net
    --- GoldED+/W32-MSVC 1.1.5-b20180707
    * Origin: Music Station | https://ms.bsrealm.net (2:5030/1997)
  • From Alexey Fayans@2:5030/1997 to Michiel van der Vlist on Mon Sep 7 17:02:32 2026
    Hello Michiel!

    On Mon, 07 Sep 2026 15:24 +0200, you wrote to Yegor Gluhov:

    FTS-4010 doesn't distinguish between secure and insecure links.
    If you are worried about problems with spoofed ping requests coming in
    via an unsecure link, just don't fly the PING flag. Simple!

    And you advice doing that instead of implementing a feature properly and securely? Wonderful.


    ... Music Station BBS | https://bbs.bsrealm.net | telnet://bbs.bsrealm.net
    --- GoldED+/W32-MSVC 1.1.5-b20180707
    * Origin: Music Station | https://ms.bsrealm.net (2:5030/1997)
  • From Yegor Gluhov@2:382/736 to Alexey Fayans on Mon Sep 7 16:41:02 2026
    Hello Alexey!

    07 Sep 26 16:44, you wrote to me:

    @MSGID: 2:382/736 6a9eb774
    @TZUTC: 0200
    @CHRS: LATIN-1 2
    [...]
    --- AmberEdit/linux 0.7.1
    Doesn't it support REPLY kludge?

    It does, but double ^A character like this one: http://temp.jegor.net/0101.png was breaking the kludges parsing. Fixed it, thanks for pointing that out.

    Yegor
    --- AmberEdit/linux 0.7.2
    * Origin: to err is human, but to really f.. things up you need AI (2:382/736)
  • From Michiel van der Vlist@2:280/5555 to Alexey Fayans on Mon Sep 7 22:01:18 2026
    Hello Alexey,

    On 07 Sep 26 16:57, you wrote to me:

    Hello Michiel!

    On Mon, 07 Sep 2026 15:22 +0200, you wrote to me:

    Still, if I wanted to spam someone with responses to PING, I
    could use such "vulnerability".

    And the gain of such an action would be?

    Would you ask the same question to a security audit of your company network infrastructure or something like that?

    1) You'r not answering the question.
    2) Knowing the motives of the attacker is usefull when designing a defence.

    When a potential vulnerability arises one should always ask the following questions:

    1) What has the potential attacker to gian?
    2) What have the attacked to loose?
    3) Is the proposed defence effective
    4) How does the proposed defence interfere with normal operation?

    My toilet hs little defince against unauthorised use? Of course I can take measures to make unauthorised use difficult or maybe even impossible. I can put locks on the door, even more than one lock. Two Factor Authorisation. But the effect will be tha I mainly make it moe difficult for myself. It os just not worth doing all that just to prevent occasional unaithorised use.

    The same goes for PING over unsecure links. It isn't really a vulnerabilty. Nothing much will happen if someone triggers a ping or a series of pings from a spoofed source. Plus that only using ping via secure links doesn't make it impossible. And it interferes with ping being a usefull tool.

    Look, I once had a mail bomb. VIA A SECURE LINK. The secure link did not protect me. OTIH, I have had PING anabled for decades. Including vis unsecure links. Never had a problem.

    Someone may want to do that just because they can. If there is an exploitable vulnerability, it will be exploited some day.

    There is nothing to "exploit". There is no problem with PING over unsecure links. PING is usefull to explore the routing. Secure or unsecure. It does jsut that. Don't fix what aint broke.

    Cheers, Michiel

    --- GoldED+/W32-MINGW 1.1.5-b20260904
    * Origin: http://www.vlist.eu (2:280/5555)
  • From Karel Kral@2:423/39 to Dmitry Protasoff on Wed Sep 9 22:25:12 2026
    Hello Dmitry!

    07 Sep 26 13:34, you wrote to Yegor Gluhov:

    With a PING response, probably, nothing.
    I use MSGID to match replies.

    Good. (In my case (checked code after years), I hardcoded sender address (did not think about RC address at all). I will remove flag from RC, makes no sense anyway. Who wants to PING .cz still can use my node address)

    Still one question: your requests came via Ward (2:5001/100 -> 2:5020/715 -> 2:292/854). I replied back via my standard Uplink (Milos, 2:423/81) Why do I see direct then?

    Karel

    --- GoldED+/LNX 1.1.5-b20240209
    * Origin: Plast DATA (2:423/39)
  • From Dmitry Protasoff@2:5001/100 to Karel Kral on Thu Sep 10 13:01:48 2026
    Hello Karel!

    In a message of 09 Sep 26 22:25, Karel wrote to Dmitry:


    Still one question: your requests came via Ward (2:5001/100 ->
    2:5020/715 -> 2:292/854). I replied back via my standard Uplink
    (Milos, 2:423/81) Why do I see direct then?

    Ah, it was just a generic "received reply on insecure link". I didn't check all the cases when implementing statuses and didn't know that some links would transfer a transit reply directly to my node even if we don't have any link configured.

    See you,
    dp.
    --- FidoMail v0.1.4-28-g57a2dff
    * Origin: livin' on the edge (2:5001/100)