Re: IRC access redux
David Krovich <[email protected]> Wed, 28 Feb 2007 19:19:53 -0500
| Newsgroups | gmane.org.user-groups.linux.morlug |
|---|---|
| Message-ID | <[email protected]> |
All, Just wanted to clarify my understanding of the situation. WVU OIT's=20 blocking of irc is not just simple port filtering. They are instead=20 doing stateful inspection and dropping any irc traffic. If it were=20 simple port blocking, I'd be able to connect to freenode on port 80 as=20 freenode runs an irc server on port 80 as well as the well known ports=20 for irc. I'm doing what I can to get irc re-enabled, but it's slow=20 going. Unfortunately, people at OIT seem to think irc is evil. Using=20 their logic they should shut down all http and https traffic since=20 sometimes those protocols are used in hacking. -Dave Matt D. Harris wrote: > It's actually true that there are a number of trojans/worms that=20 > report in via IRC. For example, a self-propagating botnet is often=20 > managed by all infected systems connecting to the botnet owner's IRC=20 > server, and being controlled by him that way. This allows a botnet=20 > maintainer to issue commands to all of his bots without having to know=20 > their individual IP addresses, etc, which would be impossible with=20 > dynamic addresses and computers that get turned off at night and=20 > such. It also allows a botnet member system to be controlled=20 > regardless of a NAT/PAT gateway, et al. > So yes, while it is a popular method of doing so, using HTTP and=20 > something like a web bulletin board is just as possible. The right=20 > answer is stateful packet inspection and a good intrusion detection=20 > and prevent system which looks for tell-tale signs of a system=20 > infection - this'll not only prevent the infected systems from=20 > operating over one method of communication, but will allow you to=20 > identify and shut down infected systems. =EF=BC=BE=EF=BC=BE > It's like the difference between sticking some chewing gum in the dam,=20 > or actually fixing the crack. > > Andrew Turnbull wrote: >> As we all know, IRC access seems to be blocked at WVU. >> >> To try getting to the bottom of things, I decided to inquire what the=20 >> official ResNet policy concerning IRC was. The answer was thus: >> >> "Mr. Turnbull, >> >> We don't have a policy against using it, but the standard IRC ports=20 >> are blocked because the University was the victim of many virus=20 >> attacks using those ports. >> >> ResNet Staff >> West Virginia University Division of Student Affairs >> Ph: (304) 293-4444 x1" >> >> Make of that what you will. If that's the case, are there any ports=20 >> that AREN'T blocked? >> >> --=20 >> Andrew Turnbull >> >> >> ----------------------------------------------------------------------= -- >> >> _______________________________________________ >> Morlug mailing list >> [email protected] >> http://mailman.morlug.org/mailman/listinfo/morlug >