LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-23-2007, 09:36 AM   #1
kaplan71
Member
 
Registered: Nov 2003
Posts: 809

Rep: Reputation: 39
System Communicating with an IRC Server


Hi there --

Our network security team contacted and informed me that one of our systems, Fedora Core 5, is communicating with an IRC server outside our network. The group has threatened to cut the system in question off the network. The system supposedly has an IRCbot running on the it.

I rebooted the server to reset the connection that it had, and I was planning on turning off all unnecessary services on the server. Besides the above, are there tools that I can use to prevent this from happening in the future? Thanks.
 
Old 07-23-2007, 12:19 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I know it's a nasty shock if you are not prepared (who's motto is that again?) but (for future reference) it would be good if people try hard to subdue the reflex to reboot *until* some stats have been taken. For instance it would be good to have listings of users, open files, processes and network connections. If unsure consult the "Intruder Detection Checklist" (CERT): http://www.cert.org/tech_tips/intrud...checklist.html before actually *doing* something.

OK, that said you *still* have to go back in and see what caused the IRC conn. because else you're not taking away the cause. While it could be a logged on user it (more often) will be some automated bot. These bots usually get inserted because of some hole in public network facing software. Think forum, bulletin board, shopping cart or similar software (and often it's patched bu the user didn't update the version).

You'll want to check out any system logs, application logs, login records, scour temp dirs for files that shouldn't be there and such. The checklist can help and while you're at it use your distro's package manager to verify package contents and run Chkrootkit and Rootkit Hunter (new beta version 1.3.0 out, hurrah!).

Any questions just ask.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How To Set Up An IRC Server And Anope IRC Services LXer Syndicated Linux News 0 02-02-2007 12:24 AM
Linux server not communicating on network... why? BadBoyMitch Linux - Networking 3 01-01-2007 06:13 PM
Linux server not communicating on network... why? BadBoyMitch Linux - Hardware 1 01-01-2007 06:11 PM
How speak irc client and irc server program? mech Linux - Networking 1 03-31-2004 05:23 PM
Communicating to a proxy server biosx Linux - Networking 3 08-01-2002 05:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration