daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-irc.md (3938B)


      1 ---
      2 title: "194,6667,6660-7000 - Pentesting IRC"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-irc.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-irc.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 194,6667,6660-7000 - Pentesting IRC
     14 
     15 ## Basic Information
     16 
     17 IRC is a text protocol. IANA assigns TCP 194 to IRC, while deployments have historically used TCP 6667 and adjacent unprivileged ports; modern networks also commonly offer TLS on 6697.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 Registration normally requires at least `NICK` and `USER`; a server may additionally require `PASS`, SASL, or other network-specific authentication. Reverse-DNS lookup is implementation/configuration dependent.<sup>[[2]](#references)</sup>
     20 
     21 Users are divided into **operators**, who need a **username** and **password** for more access, and regular **users**. Operators have varying levels of privileges, with administrators at the top.
     22 
     23 **Default ports:** 194, 6667, 6660-7000
     24 
     25 ```text
     26 PORT     STATE SERVICE
     27 6667/tcp open  irc
     28 ```
     29 
     30 ## Enumeration
     31 
     32 ### Banner
     33 
     34 IRC can support **TLS**.
     35 
     36 ```bash
     37 nc -vn <IP> <PORT>
     38 openssl s_client -connect <IP>:<PORT> -quiet
     39 ```
     40 
     41 ### Manual
     42 
     43 The following raw session registers a random nickname and exercises useful enumeration commands. Command availability and permissions vary by daemon and network; the IRC command index provides additional commands to test where supported.<sup>[[5]](#references)</sup>
     44 
     45 ```bash
     46 #Connection with random nickname
     47 USER ran213eqdw123 0 * ran213eqdw123
     48 NICK ran213eqdw123
     49 #If a PING :<random> is responded you need to send
     50 #PONG :<received random>
     51 
     52 VERSION
     53 HELP
     54 INFO
     55 LINKS
     56 HELPOP USERCMDS
     57 HELPOP OPERCMDS
     58 OPERATOR CAPA
     59 ADMIN      #Admin info
     60 USERS      #Current number of users
     61 TIME       #Server's time
     62 STATS a    #Only operators should be able to run this
     63 NAMES      #List channel names and usernames inside of each channel -> Nombre del canal y nombre de las personas que estan dentro
     64 LIST       #List channel names along with channel banner
     65 WHOIS <USERNAME>      #WHOIS a username
     66 USERHOST <USERNAME>   #If available, get hostname of a user
     67 USERIP <USERNAME>     #If available, get ip of a user
     68 JOIN <CHANNEL_NAME>   #Connect to a channel
     69 
     70 #Operator creds Brute-Force
     71 OPER <USERNAME> <PASSWORD>
     72 ```
     73 
     74 You can also test server-password authentication when the service advertises or requires it. `wealllikedebian` appeared in an old Debian/ngIRCd sample configuration and is worth testing only when that specific legacy setup is identified; it is not a universal ngIRCd default.<sup>[[3]](#references)</sup>
     75 
     76 ```bash
     77 PASS wealllikedebian
     78 NICK patrick
     79 USER test1 test2 <IP> :test3
     80 ```
     81 
     82 ### **Find and scan IRC services**
     83 
     84 ```bash
     85 nmap -sV --script irc-botnet-channels,irc-info,irc-unrealircd-backdoor -p 194,6660-7000 <ip>
     86 ```
     87 
     88 The NSE documentation describes the probes, output, and safety classification for these scripts.<sup>[[4]](#references)</sup>
     89 
     90 ### [Brute Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#irc)
     91 
     92 ### Shodan
     93 
     94 - `looking up your hostname`
     95 
     96 ## References
     97 
     98 - [1] [IANA Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
     99 - [2] [RFC 2812 - Internet Relay Chat: Client Protocol](https://www.rfc-editor.org/rfc/rfc2812)
    100 - [3] [Debian ngIRCd sample configuration](https://sources.debian.org/src/ngircd/0.10.0-1.1/debian/ngircd.conf/)
    101 - [4] [Nmap NSE - `irc-info`](https://nmap.org/nsedoc/scripts/irc-info.html)
    102 - [5] [List of IRC commands](https://en.wikipedia.org/wiki/List_of_Internet_Relay_Chat_commands#USERIP)