Re: IRC access redux

David Smith <[email protected]> Sun, 25 Mar 2007 23:47:56 +0900
Newsgroups gmane.org.user-groups.linux.morlug
Message-ID <[email protected]>
For freenode, you can try using a tor proxy or setting up an IPv6 in IPv4
tunnel, neither of which should be blocked in resnet (can anyone confirm)=
?

For oftc, the same approaches as freenode should work as well as SSL
protected IRC on ports 6697 and 9999.

Also, couldn't a Jabber transport work?

David Krovich wrote:

> All,
>=20
> Just wanted to clarify my understanding of the situation.  WVU OIT's
> blocking of irc is not just simple port filtering.  They are instead
> doing stateful inspection and dropping any irc traffic.  If it were
> simple port blocking, I'd be able to connect to freenode on port 80 as
> freenode runs an irc server on port 80 as well as the well known ports
> for irc.  I'm doing what I can to get irc re-enabled, but it's slow
> going.  Unfortunately, people at OIT seem to think irc is evil.  Using
> their logic they should shut down all http and https traffic since
> sometimes those protocols are used in hacking.
>=20
> -Dave
>=20
>=20
>=20
> Matt D. Harris wrote:
>> It's actually true that there are a number of trojans/worms that
>> report in via IRC.  For example, a self-propagating botnet is often
>> managed by all infected systems connecting to the botnet owner's IRC
>> server, and being controlled by him that way.  This allows a botnet
>> maintainer to issue commands to all of his bots without having to know
>> their individual IP addresses, etc, which would be impossible with
>> dynamic addresses and computers that get turned off at night and
>> such.  It also allows a botnet member system to be controlled
>> regardless of a NAT/PAT gateway, et al.
>> So yes, while it is a popular method of doing so, using HTTP and
>> something like a web bulletin board is just as possible.  The right
>> answer is stateful packet inspection and a good intrusion detection
>> and prevent system which looks for tell-tale signs of a system
>> infection - this'll not only prevent the infected systems from
>> operating over one method of communication, but will allow you to
>> identify and shut down infected systems.  =EF=BC=BE=EF=BC=BE
>> It's like the difference between sticking some chewing gum in the dam,
>> or actually fixing the crack.
>>
>> Andrew Turnbull wrote:
>>> As we all know, IRC access seems to be blocked at WVU.
>>>
>>> To try getting to the bottom of things, I decided to inquire what the
>>> official ResNet policy concerning IRC was.  The answer was thus:
>>>
>>> "Mr. Turnbull,
>>>
>>> We don't have a policy against using it, but the standard IRC ports
>>> are blocked because the University was the victim of many virus
>>> attacks using those ports.
>>>
>>> ResNet Staff
>>> West Virginia University Division of Student Affairs
>>> Ph: (304) 293-4444 x1"
>>>
>>> Make of that what you will.  If that's the case, are there any ports
>>> that AREN'T blocked?
>>>
>>> --
>>> Andrew Turnbull
>>>
>>>
>>> ---------------------------------------------------------------------=
---
>>>
>>> _______________________________________________
>>> Morlug mailing list
>>> [email protected]
>>> http://mailman.morlug.org/mailman/listinfo/morlug
>>