Re: IRC access redux
David Smith <[email protected]> Sun, 25 Mar 2007 23:47:56 +0900
| Newsgroups | gmane.org.user-groups.linux.morlug |
|---|---|
| Message-ID | <[email protected]> |
For freenode, you can try using a tor proxy or setting up an IPv6 in IPv4 tunnel, neither of which should be blocked in resnet (can anyone confirm)= ? For oftc, the same approaches as freenode should work as well as SSL protected IRC on ports 6697 and 9999. Also, couldn't a Jabber transport work? David Krovich wrote: > All, >=20 > Just wanted to clarify my understanding of the situation. WVU OIT's > blocking of irc is not just simple port filtering. They are instead > doing stateful inspection and dropping any irc traffic. If it were > simple port blocking, I'd be able to connect to freenode on port 80 as > freenode runs an irc server on port 80 as well as the well known ports > for irc. I'm doing what I can to get irc re-enabled, but it's slow > going. Unfortunately, people at OIT seem to think irc is evil. Using > their logic they should shut down all http and https traffic since > sometimes those protocols are used in hacking. >=20 > -Dave >=20 >=20 >=20 > Matt D. Harris wrote: >> It's actually true that there are a number of trojans/worms that >> report in via IRC. For example, a self-propagating botnet is often >> managed by all infected systems connecting to the botnet owner's IRC >> server, and being controlled by him that way. This allows a botnet >> maintainer to issue commands to all of his bots without having to know >> their individual IP addresses, etc, which would be impossible with >> dynamic addresses and computers that get turned off at night and >> such. It also allows a botnet member system to be controlled >> regardless of a NAT/PAT gateway, et al. >> So yes, while it is a popular method of doing so, using HTTP and >> something like a web bulletin board is just as possible. The right >> answer is stateful packet inspection and a good intrusion detection >> and prevent system which looks for tell-tale signs of a system >> infection - this'll not only prevent the infected systems from >> operating over one method of communication, but will allow you to >> identify and shut down infected systems. =EF=BC=BE=EF=BC=BE >> It's like the difference between sticking some chewing gum in the dam, >> or actually fixing the crack. >> >> Andrew Turnbull wrote: >>> As we all know, IRC access seems to be blocked at WVU. >>> >>> To try getting to the bottom of things, I decided to inquire what the >>> official ResNet policy concerning IRC was. The answer was thus: >>> >>> "Mr. Turnbull, >>> >>> We don't have a policy against using it, but the standard IRC ports >>> are blocked because the University was the victim of many virus >>> attacks using those ports. >>> >>> ResNet Staff >>> West Virginia University Division of Student Affairs >>> Ph: (304) 293-4444 x1" >>> >>> Make of that what you will. If that's the case, are there any ports >>> that AREN'T blocked? >>> >>> -- >>> Andrew Turnbull >>> >>> >>> ---------------------------------------------------------------------= --- >>> >>> _______________________________________________ >>> Morlug mailing list >>> [email protected] >>> http://mailman.morlug.org/mailman/listinfo/morlug >>