pentesting-irc.md (3938B)
1 --- 2 title: "194,6667,6660-7000 - Pentesting IRC" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-irc.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-irc.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 194,6667,6660-7000 - Pentesting IRC 14 15 ## Basic Information 16 17 IRC is a text protocol. IANA assigns TCP 194 to IRC, while deployments have historically used TCP 6667 and adjacent unprivileged ports; modern networks also commonly offer TLS on 6697.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 Registration normally requires at least `NICK` and `USER`; a server may additionally require `PASS`, SASL, or other network-specific authentication. Reverse-DNS lookup is implementation/configuration dependent.<sup>[[2]](#references)</sup> 20 21 Users are divided into **operators**, who need a **username** and **password** for more access, and regular **users**. Operators have varying levels of privileges, with administrators at the top. 22 23 **Default ports:** 194, 6667, 6660-7000 24 25 ```text 26 PORT STATE SERVICE 27 6667/tcp open irc 28 ``` 29 30 ## Enumeration 31 32 ### Banner 33 34 IRC can support **TLS**. 35 36 ```bash 37 nc -vn <IP> <PORT> 38 openssl s_client -connect <IP>:<PORT> -quiet 39 ``` 40 41 ### Manual 42 43 The following raw session registers a random nickname and exercises useful enumeration commands. Command availability and permissions vary by daemon and network; the IRC command index provides additional commands to test where supported.<sup>[[5]](#references)</sup> 44 45 ```bash 46 #Connection with random nickname 47 USER ran213eqdw123 0 * ran213eqdw123 48 NICK ran213eqdw123 49 #If a PING :<random> is responded you need to send 50 #PONG :<received random> 51 52 VERSION 53 HELP 54 INFO 55 LINKS 56 HELPOP USERCMDS 57 HELPOP OPERCMDS 58 OPERATOR CAPA 59 ADMIN #Admin info 60 USERS #Current number of users 61 TIME #Server's time 62 STATS a #Only operators should be able to run this 63 NAMES #List channel names and usernames inside of each channel -> Nombre del canal y nombre de las personas que estan dentro 64 LIST #List channel names along with channel banner 65 WHOIS <USERNAME> #WHOIS a username 66 USERHOST <USERNAME> #If available, get hostname of a user 67 USERIP <USERNAME> #If available, get ip of a user 68 JOIN <CHANNEL_NAME> #Connect to a channel 69 70 #Operator creds Brute-Force 71 OPER <USERNAME> <PASSWORD> 72 ``` 73 74 You can also test server-password authentication when the service advertises or requires it. `wealllikedebian` appeared in an old Debian/ngIRCd sample configuration and is worth testing only when that specific legacy setup is identified; it is not a universal ngIRCd default.<sup>[[3]](#references)</sup> 75 76 ```bash 77 PASS wealllikedebian 78 NICK patrick 79 USER test1 test2 <IP> :test3 80 ``` 81 82 ### **Find and scan IRC services** 83 84 ```bash 85 nmap -sV --script irc-botnet-channels,irc-info,irc-unrealircd-backdoor -p 194,6660-7000 <ip> 86 ``` 87 88 The NSE documentation describes the probes, output, and safety classification for these scripts.<sup>[[4]](#references)</sup> 89 90 ### [Brute Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#irc) 91 92 ### Shodan 93 94 - `looking up your hostname` 95 96 ## References 97 98 - [1] [IANA Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml) 99 - [2] [RFC 2812 - Internet Relay Chat: Client Protocol](https://www.rfc-editor.org/rfc/rfc2812) 100 - [3] [Debian ngIRCd sample configuration](https://sources.debian.org/src/ngircd/0.10.0-1.1/debian/ngircd.conf/) 101 - [4] [Nmap NSE - `irc-info`](https://nmap.org/nsedoc/scripts/irc-info.html) 102 - [5] [List of IRC commands](https://en.wikipedia.org/wiki/List_of_Internet_Relay_Chat_commands#USERIP)