Security & anti-abuse
echoIRCd's anti-abuse is a layered defence rather than a single engine, applied at the cheapest possible point in each case. (The behavioural DEFCON-style detection engine with a report-only mode lives in echo services, not in the daemon.)
The layers#
- Upstream / provider — volumetric floods (SYN/UDP/amplification) are handled before they reach the host.
- Kernel / firewall — SYN cookies, per-IP connection-rate limits, conntrack caps.
- echoIRCd — abusive sessions and content, described below.
Accept edge#
Rejection before any per-connection state is allocated:
accept_rate/accept_burst— a per-source-IP token bucket, shared across the plaintext and TLS acceptors so one IP can't get a fresh budget per listener. Trusted proxies and server links are exempt.connflood— refuse connections from an IP opening too many too fast.connectban— Z-line an IP range that opens too many connections, with a boot grace period, garbage collection, and exemptions.
Per connection#
- Clone caps — connection classes cap concurrent per-IP connections (
localmax,globalmax). registration_timeout— drop connections that never send NICK+USER.tls_handshake_timeout— reap sockets that open the TLS port but never negotiate.conn_waitpong— hold registration until the client echoes an exact PING cookie.recvq/softsendq/hardsendq— bound per-connection memory.
Per message#
- Fakelag —
flood_messagesperflood_secondsthrottles a fast client (opers exempt); a class may setfakelag=noto disconnect instead. - Channel modes
+f(message flood),+j(join flood),+F(nick-change flood).
Screening & scoring#
- DNSBL — check DNS blocklists on connect; action
mark/kill/kline/gline/zline. - Reputation — accrue a per-address score over time; surfaces the
y:extban and WHOIS. - Security groups — named AND-ed user sets usable as the
g:extban.
Content & behaviour#
antirandom (drone nick/ident/realname scoring), antimixedutf8 (look-alike mixed-script spam),
filter / badword (+G censor), solvemsg (arithmetic PM gate), recaptcha /
cloudflare_challenge (registration gates), autodrop (HTTP-scanner connections), and blockamsg
(mass /amsg). See Modules and the Configuration reference
for the keys.
Network bans#
Persistent K / G / Z / E (exempt) / Q (nick) / CBAN (channel) / SHUN / RLINE
(realname) bans; TLINE <mask> reports how many current users a would-be ban would match before you
set it.