<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.darkworld.network/index.php?action=history&amp;feed=atom&amp;title=DWIRC%3AStaff_Training%2FIRC_Operator_Fundamentals</id>
	<title>DWIRC:Staff Training/IRC Operator Fundamentals - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.darkworld.network/index.php?action=history&amp;feed=atom&amp;title=DWIRC%3AStaff_Training%2FIRC_Operator_Fundamentals"/>
	<link rel="alternate" type="text/html" href="https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;action=history"/>
	<updated>2026-08-26T19:22:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.3</generator>
	<entry>
		<id>https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=398&amp;oldid=prev</id>
		<title>Fizi: Protected &quot;DWIRC:Staff Training/IRC Operator Fundamentals&quot; ([Edit=Allow only administrators] (indefinite) [Move=Allow only administrators] (indefinite))</title>
		<link rel="alternate" type="text/html" href="https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=398&amp;oldid=prev"/>
		<updated>2026-08-08T18:07:21Z</updated>

		<summary type="html">&lt;p&gt;Protected &amp;quot;&lt;a href=&quot;/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&quot; title=&quot;DWIRC:Staff Training/IRC Operator Fundamentals&quot;&gt;DWIRC:Staff Training/IRC Operator Fundamentals&lt;/a&gt;&amp;quot; ([Edit=Allow only administrators] (indefinite) [Move=Allow only administrators] (indefinite))&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:07, 8 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;4&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff cache key mediawiki:diff:1.41:old-397:rev-398 --&gt;
&lt;/table&gt;</summary>
		<author><name>Fizi</name></author>
	</entry>
	<entry>
		<id>https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=397&amp;oldid=prev</id>
		<title>Fizi at 18:07, 8 August 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=397&amp;oldid=prev"/>
		<updated>2026-08-08T18:07:12Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;amp;diff=397&amp;amp;oldid=396&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Fizi</name></author>
	</entry>
	<entry>
		<id>https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=396&amp;oldid=prev</id>
		<title>Fizi: Created page with &quot;{{DISPLAYTITLE:Module 9 — IRC Operator Fundamentals}}  &lt;div style=&quot;background:#151515; border-left:5px solid #8b5cf6; color:#eeeeee; padding:16px; margin-bottom:20px;&quot;&gt; &lt;span style=&quot;font-size:170%; font-weight:bold;&quot;&gt;DarkWorld IRC Staff Training&lt;/span&gt;&lt;br&gt; &lt;span style=&quot;font-size:125%;&quot;&gt;Module 9: IRC Operator Fundamentals&lt;/span&gt; &lt;/div&gt;  {| class=&quot;wikitable&quot; style=&quot;width:100%;&quot; |- ! Program | DarkWorld IRC Staff Training Program |- ! Module | 9 of 10 |- ! Difficulty | Ad...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.darkworld.network/index.php?title=DWIRC:Staff_Training/IRC_Operator_Fundamentals&amp;diff=396&amp;oldid=prev"/>
		<updated>2026-08-08T18:01:10Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{DISPLAYTITLE:Module 9 — IRC Operator Fundamentals}}  &amp;lt;div style=&amp;quot;background:#151515; border-left:5px solid #8b5cf6; color:#eeeeee; padding:16px; margin-bottom:20px;&amp;quot;&amp;gt; &amp;lt;span style=&amp;quot;font-size:170%; font-weight:bold;&amp;quot;&amp;gt;DarkWorld IRC Staff Training&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt; &amp;lt;span style=&amp;quot;font-size:125%;&amp;quot;&amp;gt;Module 9: IRC Operator Fundamentals&amp;lt;/span&amp;gt; &amp;lt;/div&amp;gt;  {| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot; |- ! Program | DarkWorld IRC Staff Training Program |- ! Module | 9 of 10 |- ! Difficulty | Ad...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{DISPLAYTITLE:Module 9 — IRC Operator Fundamentals}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#151515; border-left:5px solid #8b5cf6; color:#eeeeee; padding:16px; margin-bottom:20px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:170%; font-weight:bold;&amp;quot;&amp;gt;DarkWorld IRC Staff Training&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;&amp;quot;&amp;gt;Module 9: IRC Operator Fundamentals&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Program&lt;br /&gt;
| DarkWorld IRC Staff Training Program&lt;br /&gt;
|-&lt;br /&gt;
! Module&lt;br /&gt;
| 9 of 10&lt;br /&gt;
|-&lt;br /&gt;
! Difficulty&lt;br /&gt;
| Advanced&lt;br /&gt;
|-&lt;br /&gt;
! Estimated study time&lt;br /&gt;
| 5–7 hours&lt;br /&gt;
|-&lt;br /&gt;
! Assessment&lt;br /&gt;
| Written examination, supervised laboratory, and incident simulation&lt;br /&gt;
|-&lt;br /&gt;
! Prerequisite&lt;br /&gt;
| [[DWIRC:Staff Training/Incident Handling|Module 8 — Abuse and Incident Handling]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Module Overview =&lt;br /&gt;
&lt;br /&gt;
An &amp;#039;&amp;#039;&amp;#039;IRC operator&amp;#039;&amp;#039;&amp;#039;, commonly called an &amp;#039;&amp;#039;&amp;#039;IRCOp&amp;#039;&amp;#039;&amp;#039;, is a trusted network staff member with elevated privileges for protecting and operating the IRC network.&lt;br /&gt;
&lt;br /&gt;
IRC operator access may allow a person to:&lt;br /&gt;
&lt;br /&gt;
* View additional network information.&lt;br /&gt;
* Receive operational server notices.&lt;br /&gt;
* Investigate abuse.&lt;br /&gt;
* Disconnect users.&lt;br /&gt;
* Apply network-level restrictions.&lt;br /&gt;
* Assist during floods and attacks.&lt;br /&gt;
* Coordinate incidents across servers.&lt;br /&gt;
* Override some normal channel restrictions.&lt;br /&gt;
* Perform other actions defined by their oper class.&lt;br /&gt;
&lt;br /&gt;
These powers can affect many users and must be used with restraint, accuracy, authorization, and accountability.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fdecec; border-left:4px solid #dc2626; padding:12px; margin:15px 0;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important:&amp;#039;&amp;#039;&amp;#039; Completing this lesson does not grant IRC operator access. Candidates must not use operator commands on the production network unless separately authorized and assigned an approved oper account.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Learning Objectives =&lt;br /&gt;
&lt;br /&gt;
After completing this module, the candidate should be able to:&lt;br /&gt;
&lt;br /&gt;
# Explain the purpose and limits of IRC operator access.&lt;br /&gt;
# Secure an operator account.&lt;br /&gt;
# Distinguish local and global network actions.&lt;br /&gt;
# Interpret common operational information.&lt;br /&gt;
# Investigate users without exposing private information.&lt;br /&gt;
# Explain kills and network-level restrictions.&lt;br /&gt;
# Select proportionate restriction scope and duration.&lt;br /&gt;
# Understand OperOverride and forced-mode risks.&lt;br /&gt;
# Recognize netsplits and server-link incidents.&lt;br /&gt;
# Assist safely during floods and attacks.&lt;br /&gt;
# Verify and document operator actions.&lt;br /&gt;
# Escalate high-risk commands and infrastructure issues.&lt;br /&gt;
&lt;br /&gt;
= 1. IRC Operator Role =&lt;br /&gt;
&lt;br /&gt;
IRC operators protect and support the IRC network.&lt;br /&gt;
&lt;br /&gt;
Their responsibilities may include:&lt;br /&gt;
&lt;br /&gt;
* Enforcing network-wide rules.&lt;br /&gt;
* Responding to multi-channel abuse.&lt;br /&gt;
* Investigating spam and ban evasion.&lt;br /&gt;
* Containing malicious clients or bots.&lt;br /&gt;
* Assisting during raids and floods.&lt;br /&gt;
* Monitoring authorized server notices.&lt;br /&gt;
* Coordinating with Services staff.&lt;br /&gt;
* Supporting channel staff in network-level cases.&lt;br /&gt;
* Documenting important actions.&lt;br /&gt;
* Escalating server and security incidents.&lt;br /&gt;
&lt;br /&gt;
IRC operators do not own every channel and should not interfere with ordinary channel management without a valid network-level reason.&lt;br /&gt;
&lt;br /&gt;
= 2. Operator Access Is Role-Based =&lt;br /&gt;
&lt;br /&gt;
Different IRC operators may have different permissions.&lt;br /&gt;
&lt;br /&gt;
An oper class may control:&lt;br /&gt;
&lt;br /&gt;
* Which commands are available.&lt;br /&gt;
* Which server notices are visible.&lt;br /&gt;
* Whether actions are local or global.&lt;br /&gt;
* Which users or servers can be affected.&lt;br /&gt;
* Whether override powers are available.&lt;br /&gt;
* Which administrative resources can be accessed.&lt;br /&gt;
&lt;br /&gt;
A staff title does not guarantee every IRC operator permission.&lt;br /&gt;
&lt;br /&gt;
Staff must not attempt to bypass their oper-class restrictions.&lt;br /&gt;
&lt;br /&gt;
= 3. Local and Global Actions =&lt;br /&gt;
&lt;br /&gt;
== Local Action ==&lt;br /&gt;
&lt;br /&gt;
A local action generally applies only to:&lt;br /&gt;
&lt;br /&gt;
* The current IRC server.&lt;br /&gt;
* Users connected directly to that server.&lt;br /&gt;
* A server-specific operational condition.&lt;br /&gt;
&lt;br /&gt;
== Global Action ==&lt;br /&gt;
&lt;br /&gt;
A global action may apply across the entire IRC network.&lt;br /&gt;
&lt;br /&gt;
Global actions present greater risk because they may affect:&lt;br /&gt;
&lt;br /&gt;
* Users on every server.&lt;br /&gt;
* Multiple regions.&lt;br /&gt;
* Shared providers.&lt;br /&gt;
* Relays and bouncers.&lt;br /&gt;
* Legitimate users unrelated to the incident.&lt;br /&gt;
&lt;br /&gt;
Before choosing a global action, ask whether a local or narrower restriction would solve the problem.&lt;br /&gt;
&lt;br /&gt;
= 4. Operator Account Security =&lt;br /&gt;
&lt;br /&gt;
An operator account is a privileged security credential.&lt;br /&gt;
&lt;br /&gt;
Operators must:&lt;br /&gt;
&lt;br /&gt;
* Use a strong, unique password.&lt;br /&gt;
* Never reuse a NickServ or personal password.&lt;br /&gt;
* Use TLS.&lt;br /&gt;
* Use a trusted device.&lt;br /&gt;
* Protect client configuration files.&lt;br /&gt;
* Avoid storing credentials in plaintext where possible.&lt;br /&gt;
* Avoid public or untrusted computers.&lt;br /&gt;
* Keep the operating system and IRC client updated.&lt;br /&gt;
* Secure bouncers used for operator access.&lt;br /&gt;
* Report suspected compromise immediately.&lt;br /&gt;
* Follow any approved certificate or authentication requirements.&lt;br /&gt;
* Oper only when required by current procedure.&lt;br /&gt;
&lt;br /&gt;
Operators must never:&lt;br /&gt;
&lt;br /&gt;
* Share an oper account.&lt;br /&gt;
* Give credentials to another staff member.&lt;br /&gt;
* paste an operator password into a channel.&lt;br /&gt;
* Send credentials through an unofficial bot.&lt;br /&gt;
* Leave an authorized client accessible to others.&lt;br /&gt;
* Use production access for demonstrations.&lt;br /&gt;
* Save passwords in public scripts or repositories.&lt;br /&gt;
&lt;br /&gt;
= 5. Becoming an IRC Operator =&lt;br /&gt;
&lt;br /&gt;
Traditional IRC operator authentication may use:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/OPER opername password&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
DarkWorld IRC may use additional controls, such as:&lt;br /&gt;
&lt;br /&gt;
* Restricted source hosts.&lt;br /&gt;
* TLS requirements.&lt;br /&gt;
* Client certificates.&lt;br /&gt;
* Certificate fingerprints.&lt;br /&gt;
* Security groups.&lt;br /&gt;
* Password hashing.&lt;br /&gt;
* Separate oper classes.&lt;br /&gt;
* Two-stage authorization.&lt;br /&gt;
* Approved bouncer or server access.&lt;br /&gt;
&lt;br /&gt;
Candidates must follow the current DarkWorld procedure.&lt;br /&gt;
&lt;br /&gt;
Do not demonstrate `/OPER` in public, record a real password in training material, or use another person’s oper account.&lt;br /&gt;
&lt;br /&gt;
= 6. Failed Operator Login =&lt;br /&gt;
&lt;br /&gt;
An operator login may fail because:&lt;br /&gt;
&lt;br /&gt;
* Oper name is incorrect.&lt;br /&gt;
* Password is incorrect.&lt;br /&gt;
* Source host is not authorized.&lt;br /&gt;
* TLS is not enabled.&lt;br /&gt;
* Required certificate is missing.&lt;br /&gt;
* Certificate fingerprint does not match.&lt;br /&gt;
* Oper block or class changed.&lt;br /&gt;
* Account is suspended.&lt;br /&gt;
* The user is connected to an incorrect server.&lt;br /&gt;
* Server configuration has not been reloaded correctly.&lt;br /&gt;
&lt;br /&gt;
After an unexpected failure:&lt;br /&gt;
&lt;br /&gt;
# Do not repeatedly guess passwords.&lt;br /&gt;
# Confirm TLS and the approved connection method.&lt;br /&gt;
# Record the exact error.&lt;br /&gt;
# Check whether the oper account was recently changed.&lt;br /&gt;
# Notify authorized administration.&lt;br /&gt;
# Treat unexplained repeated failures as a possible security event.&lt;br /&gt;
&lt;br /&gt;
= 7. Server Notices =&lt;br /&gt;
&lt;br /&gt;
IRC operators may receive additional server notices relating to:&lt;br /&gt;
&lt;br /&gt;
* User connections and disconnections.&lt;br /&gt;
* Failed authentication.&lt;br /&gt;
* Kills.&lt;br /&gt;
* Network bans.&lt;br /&gt;
* Flood activity.&lt;br /&gt;
* Server links and disconnections.&lt;br /&gt;
* Services activity.&lt;br /&gt;
* Operator logins.&lt;br /&gt;
* Security events.&lt;br /&gt;
* Routing issues.&lt;br /&gt;
* Configuration warnings.&lt;br /&gt;
&lt;br /&gt;
UnrealIRCd may use server-notice masks or related configuration to control which notices an operator receives.&lt;br /&gt;
&lt;br /&gt;
Staff should subscribe only to notices appropriate to their role.&lt;br /&gt;
&lt;br /&gt;
Too many notices can hide important events. Too few may prevent early detection.&lt;br /&gt;
&lt;br /&gt;
= 8. Operational Information Commands =&lt;br /&gt;
&lt;br /&gt;
Depending on permissions, useful commands may include:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/WHOIS nickname&lt;br /&gt;
/WHOIS nickname nickname&lt;br /&gt;
/WHO #channel&lt;br /&gt;
/USERHOST nickname&lt;br /&gt;
/LINKS&lt;br /&gt;
/MAP&lt;br /&gt;
/LUSERS&lt;br /&gt;
/VERSION&lt;br /&gt;
/TIME&lt;br /&gt;
/ADMIN&lt;br /&gt;
/STATS&lt;br /&gt;
/TRACE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Availability and output depend on the current UnrealIRCd version, configuration, and oper permissions.&lt;br /&gt;
&lt;br /&gt;
Candidates should use:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/HELPOP command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
or the current official server documentation before using an unfamiliar operator command.&lt;br /&gt;
&lt;br /&gt;
= 9. WHOIS for Operators =&lt;br /&gt;
&lt;br /&gt;
An operator WHOIS response may provide additional information.&lt;br /&gt;
&lt;br /&gt;
It may include:&lt;br /&gt;
&lt;br /&gt;
* Nickname.&lt;br /&gt;
* Ident.&lt;br /&gt;
* Displayed host.&lt;br /&gt;
* Registered account.&lt;br /&gt;
* Connected server.&lt;br /&gt;
* Channels.&lt;br /&gt;
* User modes.&lt;br /&gt;
* Secure connection status.&lt;br /&gt;
* Idle time.&lt;br /&gt;
* Operator status.&lt;br /&gt;
* Security-related information available to the oper class.&lt;br /&gt;
* Original connection information.&lt;br /&gt;
&lt;br /&gt;
Staff may use this information only for an authorized operational purpose.&lt;br /&gt;
&lt;br /&gt;
Hidden connection information must not be:&lt;br /&gt;
&lt;br /&gt;
* Posted publicly.&lt;br /&gt;
* Shared with channel operators unnecessarily.&lt;br /&gt;
* Used to embarrass a user.&lt;br /&gt;
* Accessed out of curiosity.&lt;br /&gt;
* Copied into unrelated cases.&lt;br /&gt;
* Used for personal retaliation.&lt;br /&gt;
&lt;br /&gt;
= 10. Investigating a User =&lt;br /&gt;
&lt;br /&gt;
Before using elevated information, identify:&lt;br /&gt;
&lt;br /&gt;
* The reported conduct.&lt;br /&gt;
* The applicable policy.&lt;br /&gt;
* The relevant time.&lt;br /&gt;
* The channel or recipients.&lt;br /&gt;
* Evidence already available.&lt;br /&gt;
* Whether the incident is ongoing.&lt;br /&gt;
* Whether the requested information is necessary.&lt;br /&gt;
* Whether you have permission to access it.&lt;br /&gt;
&lt;br /&gt;
An investigation should remain limited to the incident.&lt;br /&gt;
&lt;br /&gt;
Do not expand a routine spam report into a broad search of unrelated user activity without authorization.&lt;br /&gt;
&lt;br /&gt;
= 11. Identity Correlation =&lt;br /&gt;
&lt;br /&gt;
Operators may observe connections that share:&lt;br /&gt;
&lt;br /&gt;
* IP addresses.&lt;br /&gt;
* Hostnames.&lt;br /&gt;
* Idents.&lt;br /&gt;
* Accounts.&lt;br /&gt;
* Certificates.&lt;br /&gt;
* Bouncers.&lt;br /&gt;
* VPN exits.&lt;br /&gt;
* Proxies.&lt;br /&gt;
* Gateways.&lt;br /&gt;
* Behavioral patterns.&lt;br /&gt;
&lt;br /&gt;
Shared information does not automatically prove common control.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
* A household may share one address.&lt;br /&gt;
* A university or company may use shared NAT.&lt;br /&gt;
* A VPN exit may serve many customers.&lt;br /&gt;
* A ZNC provider may host many users.&lt;br /&gt;
* A web gateway may show similar connection information.&lt;br /&gt;
* IPv6 users may rotate addresses within an assigned range.&lt;br /&gt;
&lt;br /&gt;
Identity conclusions should use multiple relevant indicators and be stated carefully.&lt;br /&gt;
&lt;br /&gt;
= 12. KILL =&lt;br /&gt;
&lt;br /&gt;
A kill disconnects a user from IRC.&lt;br /&gt;
&lt;br /&gt;
General syntax:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/KILL nickname reason&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example used only for an authorized training environment:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/KILL TestUser Active multi-channel flooding&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A kill:&lt;br /&gt;
&lt;br /&gt;
* Ends the current IRC connection.&lt;br /&gt;
* Does not necessarily prevent reconnection.&lt;br /&gt;
* Does not automatically ban an account or address.&lt;br /&gt;
* May be appropriate for immediate containment.&lt;br /&gt;
* Must include a professional reason.&lt;br /&gt;
* Should be recorded when significant.&lt;br /&gt;
&lt;br /&gt;
== Appropriate Uses May Include ==&lt;br /&gt;
&lt;br /&gt;
* Active multi-channel flooding.&lt;br /&gt;
* Credential phishing.&lt;br /&gt;
* Malicious bot activity.&lt;br /&gt;
* Severe ongoing network abuse.&lt;br /&gt;
* Immediate containment during an investigation.&lt;br /&gt;
&lt;br /&gt;
== Inappropriate Uses Include ==&lt;br /&gt;
&lt;br /&gt;
* Personal disagreement.&lt;br /&gt;
* Minor channel-rule violations.&lt;br /&gt;
* User criticism of staff.&lt;br /&gt;
* Demonstrations or jokes.&lt;br /&gt;
* Avoiding ordinary channel moderation.&lt;br /&gt;
* Disconnecting someone without checking the target.&lt;br /&gt;
&lt;br /&gt;
= 13. Network-Level Restrictions =&lt;br /&gt;
&lt;br /&gt;
UnrealIRCd may provide several restriction types.&lt;br /&gt;
&lt;br /&gt;
Exact syntax, matching behavior, storage, and scope must be confirmed with the current server help and DarkWorld procedures.&lt;br /&gt;
&lt;br /&gt;
Possible types include:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
! Restriction&lt;br /&gt;
! General purpose&lt;br /&gt;
! Main concern&lt;br /&gt;
|-&lt;br /&gt;
| Local connection ban&lt;br /&gt;
| Restricts matching users on one server&lt;br /&gt;
| May not protect other servers&lt;br /&gt;
|-&lt;br /&gt;
| Global connection ban&lt;br /&gt;
| Restricts matching users network-wide&lt;br /&gt;
| May affect many legitimate users&lt;br /&gt;
|-&lt;br /&gt;
| IP-based restriction&lt;br /&gt;
| Restricts a specific address or range&lt;br /&gt;
| Shared or dynamic addresses&lt;br /&gt;
|-&lt;br /&gt;
| Z-line-style restriction&lt;br /&gt;
| Blocks matching IP connections at an early stage&lt;br /&gt;
| Very broad and difficult for affected users&lt;br /&gt;
|-&lt;br /&gt;
| Shun-style restriction&lt;br /&gt;
| Silently limits many commands from a user&lt;br /&gt;
| User may not understand what is happening&lt;br /&gt;
|-&lt;br /&gt;
| Temporary restriction&lt;br /&gt;
| Expires automatically after a duration&lt;br /&gt;
| Duration and matching must still be accurate&lt;br /&gt;
|-&lt;br /&gt;
| Permanent restriction&lt;br /&gt;
| Remains until removed&lt;br /&gt;
| Requires strong justification and review&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Common UnrealIRCd command names may include:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
KLINE&lt;br /&gt;
GLINE&lt;br /&gt;
ZLINE&lt;br /&gt;
GZLINE&lt;br /&gt;
SHUN&lt;br /&gt;
TEMPSHUN&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This list is informational. Candidates must not execute these commands on production without explicit authorization.&lt;br /&gt;
&lt;br /&gt;
= 14. Restriction Selection =&lt;br /&gt;
&lt;br /&gt;
Before applying a network restriction, determine:&lt;br /&gt;
&lt;br /&gt;
# Is a network-level restriction required?&lt;br /&gt;
# Is the incident still active?&lt;br /&gt;
# Which identity or connection property should match?&lt;br /&gt;
# Is the target shared?&lt;br /&gt;
# Would a local restriction be sufficient?&lt;br /&gt;
# Would an account-based action be more accurate?&lt;br /&gt;
# What duration is proportionate?&lt;br /&gt;
# How many legitimate users may be affected?&lt;br /&gt;
# Is there a documented reason?&lt;br /&gt;
# Who authorized the action?&lt;br /&gt;
# How will the restriction be reviewed and removed?&lt;br /&gt;
&lt;br /&gt;
= 15. Restriction Scope =&lt;br /&gt;
&lt;br /&gt;
Possible scope choices include:&lt;br /&gt;
&lt;br /&gt;
* One current connection.&lt;br /&gt;
* One account.&lt;br /&gt;
* One visible user mask.&lt;br /&gt;
* One IP address.&lt;br /&gt;
* One hostname.&lt;br /&gt;
* One IPv4 range.&lt;br /&gt;
* One IPv6 prefix.&lt;br /&gt;
* One provider or autonomous network.&lt;br /&gt;
* One server.&lt;br /&gt;
* The entire IRC network.&lt;br /&gt;
&lt;br /&gt;
As scope grows, risk grows.&lt;br /&gt;
&lt;br /&gt;
A provider-wide restriction should not be selected merely because it is easier than identifying the actual source.&lt;br /&gt;
&lt;br /&gt;
= 16. IPv4 and IPv6 Considerations =&lt;br /&gt;
&lt;br /&gt;
== IPv4 ==&lt;br /&gt;
&lt;br /&gt;
Multiple users may share one public IPv4 address because of:&lt;br /&gt;
&lt;br /&gt;
* Home routers.&lt;br /&gt;
* Carrier-grade NAT.&lt;br /&gt;
* Business networks.&lt;br /&gt;
* VPNs.&lt;br /&gt;
* Bouncers.&lt;br /&gt;
* Web gateways.&lt;br /&gt;
&lt;br /&gt;
== IPv6 ==&lt;br /&gt;
&lt;br /&gt;
IPv6 users may have:&lt;br /&gt;
&lt;br /&gt;
* A stable individual address.&lt;br /&gt;
* Temporary privacy addresses.&lt;br /&gt;
* Multiple addresses.&lt;br /&gt;
* An assigned prefix.&lt;br /&gt;
* Rotating interface identifiers.&lt;br /&gt;
&lt;br /&gt;
An IPv6 restriction that is too narrow may be easily avoided. One that is too broad may block many unrelated systems.&lt;br /&gt;
&lt;br /&gt;
Prefix-based decisions should be made only by trained and authorized staff using accurate network information.&lt;br /&gt;
&lt;br /&gt;
= 17. Restriction Duration =&lt;br /&gt;
&lt;br /&gt;
Possible durations might include:&lt;br /&gt;
&lt;br /&gt;
* A few minutes during active flooding.&lt;br /&gt;
* Several hours.&lt;br /&gt;
* One day.&lt;br /&gt;
* Several days.&lt;br /&gt;
* A longer reviewed period.&lt;br /&gt;
* Indefinite, only where properly authorized.&lt;br /&gt;
&lt;br /&gt;
Duration should reflect:&lt;br /&gt;
&lt;br /&gt;
* Severity.&lt;br /&gt;
* Repetition.&lt;br /&gt;
* Likelihood of recurrence.&lt;br /&gt;
* Previous relevant history.&lt;br /&gt;
* Shared-host impact.&lt;br /&gt;
* Whether the source was compromised.&lt;br /&gt;
* Whether the actor cooperated.&lt;br /&gt;
* Whether the incident remains under investigation.&lt;br /&gt;
&lt;br /&gt;
Temporary restrictions are often safer during an evolving incident because they force a later decision instead of remaining forgotten.&lt;br /&gt;
&lt;br /&gt;
= 18. Restriction Reasons =&lt;br /&gt;
&lt;br /&gt;
A network-restriction reason should be:&lt;br /&gt;
&lt;br /&gt;
* Specific.&lt;br /&gt;
* Factual.&lt;br /&gt;
* Professional.&lt;br /&gt;
* Connected to policy.&lt;br /&gt;
* Understandable during review.&lt;br /&gt;
* Free from unnecessary sensitive information.&lt;br /&gt;
&lt;br /&gt;
Good examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Active multi-channel flooding&lt;br /&gt;
Credential phishing through NickServ impersonation&lt;br /&gt;
Repeated network advertising after warning&lt;br /&gt;
Ban evasion during active harassment incident&lt;br /&gt;
Malicious relay activity pending compliance review&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Poor examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Bad user&lt;br /&gt;
Go away&lt;br /&gt;
Annoying&lt;br /&gt;
Staff decision&lt;br /&gt;
You know why&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where supported by procedure, include an internal case reference.&lt;br /&gt;
&lt;br /&gt;
= 19. Verifying an Operator Action =&lt;br /&gt;
&lt;br /&gt;
After sending an elevated command:&lt;br /&gt;
&lt;br /&gt;
# Read the server response.&lt;br /&gt;
# Confirm the intended target.&lt;br /&gt;
# Confirm the scope.&lt;br /&gt;
# Confirm the duration.&lt;br /&gt;
# Check the relevant restriction list or logs.&lt;br /&gt;
# Verify that the incident stopped.&lt;br /&gt;
# Check for unintended impact.&lt;br /&gt;
# Record the action.&lt;br /&gt;
# Set a review time.&lt;br /&gt;
&lt;br /&gt;
Never assume success merely because the command was sent.&lt;br /&gt;
&lt;br /&gt;
= 20. Removing Restrictions =&lt;br /&gt;
&lt;br /&gt;
Before removing a restriction:&lt;br /&gt;
&lt;br /&gt;
* Confirm the exact entry.&lt;br /&gt;
* Confirm the original reason.&lt;br /&gt;
* Check whether the incident is resolved.&lt;br /&gt;
* Check whether another active case depends on it.&lt;br /&gt;
* Confirm your authority.&lt;br /&gt;
* Record who removed it and why.&lt;br /&gt;
* Monitor for recurrence.&lt;br /&gt;
&lt;br /&gt;
Do not remove another operator’s restriction merely because the affected user asks privately.&lt;br /&gt;
&lt;br /&gt;
Use the appeal and review procedure.&lt;br /&gt;
&lt;br /&gt;
= 21. Shuns and Silent Restrictions =&lt;br /&gt;
&lt;br /&gt;
A shun-style action may cause many user commands or messages to be ignored while the connection remains active.&lt;br /&gt;
&lt;br /&gt;
Possible benefits:&lt;br /&gt;
&lt;br /&gt;
* Limits an active abusive client.&lt;br /&gt;
* Reduces immediate disruption.&lt;br /&gt;
* Gives staff time to investigate.&lt;br /&gt;
* May prevent an automated client from adapting immediately.&lt;br /&gt;
&lt;br /&gt;
Risks:&lt;br /&gt;
&lt;br /&gt;
* The user may not know why commands fail.&lt;br /&gt;
* Legitimate support requests may be blocked.&lt;br /&gt;
* The restriction may be forgotten.&lt;br /&gt;
* It may complicate evidence.&lt;br /&gt;
* It can be abused as an invisible punishment.&lt;br /&gt;
&lt;br /&gt;
Shuns should be authorized, documented, reviewed, and removed removed when no longer needed.&lt;br /&gt;
&lt;br /&gt;
= 22. OperOverride =&lt;br /&gt;
&lt;br /&gt;
OperOverride may allow an IRC operator to bypass normal channel restrictions.&lt;br /&gt;
&lt;br /&gt;
Depending on configuration, it may permit actions such as:&lt;br /&gt;
&lt;br /&gt;
* Joining a restricted channel.&lt;br /&gt;
* Acting despite channel access limits.&lt;br /&gt;
* Changing modes without normal channel privileges.&lt;br /&gt;
* Performing emergency intervention.&lt;br /&gt;
&lt;br /&gt;
OperOverride must be limited to valid network duties.&lt;br /&gt;
&lt;br /&gt;
Appropriate examples may include:&lt;br /&gt;
&lt;br /&gt;
* Stopping an active serious policy violation.&lt;br /&gt;
* Responding to a channel takeover.&lt;br /&gt;
* Entering a channel during an urgent network incident.&lt;br /&gt;
* Protecting users when normal channel management is unavailable.&lt;br /&gt;
&lt;br /&gt;
Inappropriate examples include:&lt;br /&gt;
&lt;br /&gt;
* Joining a private channel out of curiosity.&lt;br /&gt;
* Overriding a channel founder during a personal dispute.&lt;br /&gt;
* Obtaining operator status for entertainment.&lt;br /&gt;
* Monitoring private conversations without authorization.&lt;br /&gt;
* Avoiding the normal appeal or Services process.&lt;br /&gt;
&lt;br /&gt;
= 23. SAMODE and Forced Modes =&lt;br /&gt;
&lt;br /&gt;
Forced-mode commands may allow authorized IRC operators to change:&lt;br /&gt;
&lt;br /&gt;
* Channel modes.&lt;br /&gt;
* User status.&lt;br /&gt;
* User modes.&lt;br /&gt;
* Other protected state.&lt;br /&gt;
&lt;br /&gt;
These commands can override normal channel authority and must be treated as high risk.&lt;br /&gt;
&lt;br /&gt;
Before using a forced mode:&lt;br /&gt;
&lt;br /&gt;
# Confirm the target.&lt;br /&gt;
# Confirm the current state.&lt;br /&gt;
# Identify the network-level reason.&lt;br /&gt;
# Obtain required authorization.&lt;br /&gt;
# Use the smallest effective change.&lt;br /&gt;
# Record the previous state.&lt;br /&gt;
# Apply the change.&lt;br /&gt;
# Verify the result.&lt;br /&gt;
# Restore or review it afterward.&lt;br /&gt;
&lt;br /&gt;
A forced mode should never be used merely because it is faster than contacting the channel founder or using ChanServ correctly.&lt;br /&gt;
&lt;br /&gt;
= 24. Server Links and Netsplits =&lt;br /&gt;
&lt;br /&gt;
DarkWorld IRC uses multiple linked servers.&lt;br /&gt;
&lt;br /&gt;
A server-link problem may cause:&lt;br /&gt;
&lt;br /&gt;
* Many users to quit simultaneously.&lt;br /&gt;
* Channels to temporarily split.&lt;br /&gt;
* Duplicate state on separate sides.&lt;br /&gt;
* Services access to disappear temporarily.&lt;br /&gt;
* Servers to reconnect repeatedly.&lt;br /&gt;
* Large groups of users to return.&lt;br /&gt;
* Mode synchronization activity.&lt;br /&gt;
&lt;br /&gt;
Operators should distinguish:&lt;br /&gt;
&lt;br /&gt;
* A normal user disconnection.&lt;br /&gt;
* A server ping timeout.&lt;br /&gt;
* A netsplit.&lt;br /&gt;
* A deliberate server disconnect.&lt;br /&gt;
* A routing or TLS link failure.&lt;br /&gt;
* A server under attack.&lt;br /&gt;
&lt;br /&gt;
== Operator Response ==&lt;br /&gt;
&lt;br /&gt;
# Identify the affected server.&lt;br /&gt;
# Record the time.&lt;br /&gt;
# Review authorized server notices.&lt;br /&gt;
# Notify network operations.&lt;br /&gt;
# Avoid unnecessary global restrictions.&lt;br /&gt;
# Avoid promising an unsupported cause.&lt;br /&gt;
# Allow synchronization after reconnection.&lt;br /&gt;
# Check whether channels and Services recovered.&lt;br /&gt;
# Document persistent or repeated failures.&lt;br /&gt;
&lt;br /&gt;
= 25. Server Administration Commands =&lt;br /&gt;
&lt;br /&gt;
UnrealIRCd may provide commands capable of:&lt;br /&gt;
&lt;br /&gt;
* Connecting a server.&lt;br /&gt;
* Disconnecting a server.&lt;br /&gt;
* Rehashing configuration.&lt;br /&gt;
* Restarting a server.&lt;br /&gt;
* Shutting down a server.&lt;br /&gt;
* Changing routing.&lt;br /&gt;
* Broadcasting network notices.&lt;br /&gt;
&lt;br /&gt;
Examples may include command names such as:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CONNECT&lt;br /&gt;
SQUIT&lt;br /&gt;
REHASH&lt;br /&gt;
RESTART&lt;br /&gt;
DIE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background:#fdecec; border-left:4px solid #dc2626; padding:12px; margin:15px 0;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Critical restriction:&amp;#039;&amp;#039;&amp;#039; These are server-administration commands, not general IRC operator tools. They must not be used by trainees or unauthorized operators.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Incorrect use may:&lt;br /&gt;
&lt;br /&gt;
* Disconnect hundreds of users.&lt;br /&gt;
* Split the network.&lt;br /&gt;
* Interrupt Services.&lt;br /&gt;
* Prevent reconnection.&lt;br /&gt;
* Apply broken configuration.&lt;br /&gt;
* Create a security incident.&lt;br /&gt;
&lt;br /&gt;
Detailed use belongs in the separate IRCd Administration Program.&lt;br /&gt;
&lt;br /&gt;
= 26. Flood and Attack Response =&lt;br /&gt;
&lt;br /&gt;
Network attacks may include:&lt;br /&gt;
&lt;br /&gt;
* Connection floods.&lt;br /&gt;
* Registration floods.&lt;br /&gt;
* Nickname floods.&lt;br /&gt;
* Join floods.&lt;br /&gt;
* Distributed message floods.&lt;br /&gt;
* CTCP floods.&lt;br /&gt;
* Reconnect loops.&lt;br /&gt;
* Malicious bot networks.&lt;br /&gt;
* Targeted server attacks.&lt;br /&gt;
&lt;br /&gt;
An IRC operator should:&lt;br /&gt;
&lt;br /&gt;
# Confirm the observed behavior.&lt;br /&gt;
# Determine affected servers and channels.&lt;br /&gt;
# Notify the incident lead.&lt;br /&gt;
# Apply only approved protective measures.&lt;br /&gt;
# Avoid broad reactive bans without impact review.&lt;br /&gt;
# Preserve server notices and timestamps.&lt;br /&gt;
# Coordinate with IRCd administrators.&lt;br /&gt;
# Monitor whether the attack changes method.&lt;br /&gt;
# Record temporary actions.&lt;br /&gt;
# Review and remove emergency restrictions later.&lt;br /&gt;
&lt;br /&gt;
IRC operators should not independently change firewalls, IRCd configuration, DNS, or provider-level protection unless separately authorized.&lt;br /&gt;
&lt;br /&gt;
= 27. Network Notices =&lt;br /&gt;
&lt;br /&gt;
Authorized operators may send notices to:&lt;br /&gt;
&lt;br /&gt;
* One user.&lt;br /&gt;
* One server’s users.&lt;br /&gt;
* All network users.&lt;br /&gt;
* Specific staff groups.&lt;br /&gt;
&lt;br /&gt;
Network-wide notices should be reserved for information that users need.&lt;br /&gt;
&lt;br /&gt;
A good notice is:&lt;br /&gt;
&lt;br /&gt;
* Accurate.&lt;br /&gt;
* Short.&lt;br /&gt;
* Actionable.&lt;br /&gt;
* Professionally written.&lt;br /&gt;
* Approved where required.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DarkWorld IRC is investigating a temporary connectivity issue affecting some users. Please avoid repeated reconnect attempts and monitor #Help for updates.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Avoid:&lt;br /&gt;
&lt;br /&gt;
* Personal announcements.&lt;br /&gt;
* Arguments.&lt;br /&gt;
* Unverified claims.&lt;br /&gt;
* Public accusations.&lt;br /&gt;
* Excessive repeated notices.&lt;br /&gt;
* Confidential incident details.&lt;br /&gt;
* Advertising unrelated to network operations.&lt;br /&gt;
&lt;br /&gt;
= 28. Services and IRC Operator Boundaries =&lt;br /&gt;
&lt;br /&gt;
IRC operator access and Services administration are separate.&lt;br /&gt;
&lt;br /&gt;
An IRC operator may be able to:&lt;br /&gt;
&lt;br /&gt;
* Disconnect an abusive user.&lt;br /&gt;
* Apply an authorized connection restriction.&lt;br /&gt;
* Respond to a network attack.&lt;br /&gt;
* Review operational information.&lt;br /&gt;
&lt;br /&gt;
They may not automatically be authorized to:&lt;br /&gt;
&lt;br /&gt;
* Change a NickServ account owner.&lt;br /&gt;
* Change a ChanServ founder.&lt;br /&gt;
* Drop registered accounts or channels.&lt;br /&gt;
* Suspend Services records.&lt;br /&gt;
* Modify the Anope database.&lt;br /&gt;
* Assign vhosts.&lt;br /&gt;
* Use all OperServ commands.&lt;br /&gt;
&lt;br /&gt;
Services actions require the appropriate Services role.&lt;br /&gt;
&lt;br /&gt;
= 29. Other DarkWorld Project Boundaries =&lt;br /&gt;
&lt;br /&gt;
IRC operator access does not authorize the operator to:&lt;br /&gt;
&lt;br /&gt;
* Access DWShells servers.&lt;br /&gt;
* Suspend shell accounts.&lt;br /&gt;
* Modify DWBouncers users.&lt;br /&gt;
* Access project databases.&lt;br /&gt;
* Change websites.&lt;br /&gt;
* Manage unrelated project applications.&lt;br /&gt;
* Use server credentials belonging to another team.&lt;br /&gt;
&lt;br /&gt;
If IRC abuse originates from another DarkWorld project:&lt;br /&gt;
&lt;br /&gt;
# Protect the IRC network.&lt;br /&gt;
# Preserve relevant evidence.&lt;br /&gt;
# Notify the relevant project team.&lt;br /&gt;
# Separate IRC action from project action.&lt;br /&gt;
# Coordinate through authorized staff.&lt;br /&gt;
# Record cross-project decisions.&lt;br /&gt;
&lt;br /&gt;
= 30. Operator Logs and Accountability =&lt;br /&gt;
&lt;br /&gt;
Important operator actions should be logged.&lt;br /&gt;
&lt;br /&gt;
A record may include:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Date and time:&lt;br /&gt;
Operator:&lt;br /&gt;
Command or action:&lt;br /&gt;
Target:&lt;br /&gt;
Scope:&lt;br /&gt;
Duration:&lt;br /&gt;
Reason:&lt;br /&gt;
Policy or incident reference:&lt;br /&gt;
Evidence location:&lt;br /&gt;
Authorized by:&lt;br /&gt;
Result:&lt;br /&gt;
Unexpected impact:&lt;br /&gt;
Review date:&lt;br /&gt;
Removal or expiry:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Operator logs must not be altered to conceal mistakes.&lt;br /&gt;
&lt;br /&gt;
Where sensitive information is required, access to the record should be restricted appropriately.&lt;br /&gt;
&lt;br /&gt;
= 31. Mistakes and Emergency Correction =&lt;br /&gt;
&lt;br /&gt;
If an operator affects the wrong user or scope:&lt;br /&gt;
&lt;br /&gt;
# Stop continuing harm.&lt;br /&gt;
# Correct or remove the action.&lt;br /&gt;
# Verify recovery.&lt;br /&gt;
# Notify the incident lead or senior staff.&lt;br /&gt;
# Inform affected users appropriately.&lt;br /&gt;
# Preserve the original command record.&lt;br /&gt;
# Record the correction.&lt;br /&gt;
# Review why the mistake occurred.&lt;br /&gt;
# Improve the procedure.&lt;br /&gt;
&lt;br /&gt;
Operators should not hide mistakes out of fear of criticism. Concealment creates a greater trust and security problem.&lt;br /&gt;
&lt;br /&gt;
= 32. Operator Conflicts of Interest =&lt;br /&gt;
&lt;br /&gt;
An operator should not be the sole decision-maker when:&lt;br /&gt;
&lt;br /&gt;
* They are personally involved.&lt;br /&gt;
* A friend or project associate is involved.&lt;br /&gt;
* They previously argued with the user.&lt;br /&gt;
* Their own action is being appealed.&lt;br /&gt;
* They may benefit from the restriction.&lt;br /&gt;
* They have publicly prejudged the case.&lt;br /&gt;
&lt;br /&gt;
During immediate danger, they may take the minimum protective action and then transfer the matter to a neutral reviewer.&lt;br /&gt;
&lt;br /&gt;
= 33. Operator Handover =&lt;br /&gt;
&lt;br /&gt;
When leaving an active incident, provide:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Incident reference:&lt;br /&gt;
Current incident lead:&lt;br /&gt;
Affected users/channels/servers:&lt;br /&gt;
Confirmed facts:&lt;br /&gt;
Active network restrictions:&lt;br /&gt;
Restriction scope:&lt;br /&gt;
Restriction duration:&lt;br /&gt;
Reason:&lt;br /&gt;
Evidence location:&lt;br /&gt;
Server or Services state:&lt;br /&gt;
Teams notified:&lt;br /&gt;
Pending actions:&lt;br /&gt;
Next review time:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The receiving operator should confirm acceptance.&lt;br /&gt;
&lt;br /&gt;
= 34. Practical Laboratory Rules =&lt;br /&gt;
&lt;br /&gt;
Operator exercises must use:&lt;br /&gt;
&lt;br /&gt;
* A dedicated test server, or&lt;br /&gt;
* An approved isolated training environment, or&lt;br /&gt;
* A trainer-controlled simulation.&lt;br /&gt;
&lt;br /&gt;
Production operator commands must not be used for practice.&lt;br /&gt;
&lt;br /&gt;
The laboratory should use:&lt;br /&gt;
&lt;br /&gt;
* Test accounts.&lt;br /&gt;
* Test channels.&lt;br /&gt;
* Non-production oper credentials.&lt;/div&gt;</summary>
		<author><name>Fizi</name></author>
	</entry>
</feed>