<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: System Communicating with an IRC Server in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042011#M29441</link>
    <description>block this ports using tcp warpers or iptables.  &lt;BR /&gt;&lt;BR /&gt;194/tcp/udp&lt;BR /&gt;529/tcp/udp</description>
    <pubDate>Mon, 23 Jul 2007 23:08:08 GMT</pubDate>
    <dc:creator>sshakthi</dc:creator>
    <dc:date>2007-07-23T23:08:08Z</dc:date>
    <item>
      <title>System Communicating with an IRC Server</title>
      <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042009#M29439</link>
      <description>Hi there --&lt;BR /&gt;&lt;BR /&gt;Our network security team contacted and informed me that one of our systems, Fedora Core 5, is communicating with an IRC server outside our network. The group has threatened to cut the system in question off the network. The system supposedly has an IRCbot running on the it. &lt;BR /&gt;&lt;BR /&gt;I rebooted the server to reset the connection that it had, and I was planning on turning off all unnecessary services on the server. Besides the above, are there tools that I can use to prevent this from happening in the future? Thanks.</description>
      <pubDate>Mon, 23 Jul 2007 10:07:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042009#M29439</guid>
      <dc:creator>Andrew Kaplan</dc:creator>
      <dc:date>2007-07-23T10:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: System Communicating with an IRC Server</title>
      <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042010#M29440</link>
      <description>Start by setting the firewall to block all external traffic, and ensuring user security (passwords etc.).&lt;BR /&gt;&lt;BR /&gt;It sounds like you've been root-kit'd.&lt;BR /&gt;&lt;BR /&gt;So use 'rpm -Va' to verify that none of the binaries have been replaced, use 'netstat -ntlp', 'ps', and the contents of '/proc' to ensure you don't have any hidden processes.</description>
      <pubDate>Mon, 23 Jul 2007 15:47:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042010#M29440</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2007-07-23T15:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: System Communicating with an IRC Server</title>
      <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042011#M29441</link>
      <description>block this ports using tcp warpers or iptables.  &lt;BR /&gt;&lt;BR /&gt;194/tcp/udp&lt;BR /&gt;529/tcp/udp</description>
      <pubDate>Mon, 23 Jul 2007 23:08:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042011#M29441</guid>
      <dc:creator>sshakthi</dc:creator>
      <dc:date>2007-07-23T23:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: System Communicating with an IRC Server</title>
      <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042012#M29442</link>
      <description>you may make use of nmap to veiry the port status.&lt;BR /&gt;&lt;BR /&gt;example&lt;BR /&gt;nmap -v -p 194 xx.xx.xx.xx</description>
      <pubDate>Wed, 25 Jul 2007 21:01:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042012#M29442</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-07-25T21:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: System Communicating with an IRC Server</title>
      <link>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042013#M29443</link>
      <description>I would block the access for this server to/from internet until things had been resolved.&lt;BR /&gt;&lt;BR /&gt;If this server has been root'ed you might not find anything using normal tools, and you might need to use [url=&lt;A href="http://www.sleuthkit.org/]SleuthKit[/url]" target="_blank"&gt;http://www.sleuthkit.org/]SleuthKit[/url]&lt;/A&gt; and [url=&lt;A href="http://liveview.sourceforge.net/]LiveView[/url]" target="_blank"&gt;http://liveview.sourceforge.net/]LiveView[/url]&lt;/A&gt; to track down the culprits.&lt;BR /&gt;&lt;BR /&gt;You should also check the firewall logs for any unusual traffic to/from this host, and after you've put the system back up on the network again you should setup tcpdump to log such activity.&lt;BR /&gt;&lt;BR /&gt;Lars</description>
      <pubDate>Mon, 30 Jul 2007 12:49:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/system-communicating-with-an-irc-server/m-p/4042013#M29443</guid>
      <dc:creator>larstr</dc:creator>
      <dc:date>2007-07-30T12:49:58Z</dc:date>
    </item>
  </channel>
</rss>

