Re: IRC access redux

David Krovich <[email protected]> Wed, 28 Feb 2007 19:19:53 -0500
Newsgroups gmane.org.user-groups.linux.morlug
Message-ID <[email protected]>
All,

Just wanted to clarify my understanding of the situation.  WVU OIT's=20
blocking of irc is not just simple port filtering.  They are instead=20
doing stateful inspection and dropping any irc traffic.  If it were=20
simple port blocking, I'd be able to connect to freenode on port 80 as=20
freenode runs an irc server on port 80 as well as the well known ports=20
for irc.  I'm doing what I can to get irc re-enabled, but it's slow=20
going.  Unfortunately, people at OIT seem to think irc is evil.  Using=20
their logic they should shut down all http and https traffic since=20
sometimes those protocols are used in hacking.

-Dave



Matt D. Harris wrote:
> It's actually true that there are a number of trojans/worms that=20
> report in via IRC.  For example, a self-propagating botnet is often=20
> managed by all infected systems connecting to the botnet owner's IRC=20
> server, and being controlled by him that way.  This allows a botnet=20
> maintainer to issue commands to all of his bots without having to know=20
> their individual IP addresses, etc, which would be impossible with=20
> dynamic addresses and computers that get turned off at night and=20
> such.  It also allows a botnet member system to be controlled=20
> regardless of a NAT/PAT gateway, et al.
> So yes, while it is a popular method of doing so, using HTTP and=20
> something like a web bulletin board is just as possible.  The right=20
> answer is stateful packet inspection and a good intrusion detection=20
> and prevent system which looks for tell-tale signs of a system=20
> infection - this'll not only prevent the infected systems from=20
> operating over one method of communication, but will allow you to=20
> identify and shut down infected systems.  =EF=BC=BE=EF=BC=BE
> It's like the difference between sticking some chewing gum in the dam,=20
> or actually fixing the crack.
>
> Andrew Turnbull wrote:
>> As we all know, IRC access seems to be blocked at WVU.
>>
>> To try getting to the bottom of things, I decided to inquire what the=20
>> official ResNet policy concerning IRC was.  The answer was thus:
>>
>> "Mr. Turnbull,
>>
>> We don't have a policy against using it, but the standard IRC ports=20
>> are blocked because the University was the victim of many virus=20
>> attacks using those ports.
>>
>> ResNet Staff
>> West Virginia University Division of Student Affairs
>> Ph: (304) 293-4444 x1"
>>
>> Make of that what you will.  If that's the case, are there any ports=20
>> that AREN'T blocked?
>>
>> --=20
>> Andrew Turnbull
>>
>>
>> ----------------------------------------------------------------------=
--
>>
>> _______________________________________________
>> Morlug mailing list
>> [email protected]
>> http://mailman.morlug.org/mailman/listinfo/morlug
>