All of lore.kernel.org
 help / color / mirror / Atom feed
* blocking irc + botnets
@ 2005-08-02 15:41 hbeaumont hbeaumont
  2005-08-02 16:55 ` Daniel Lopes
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: hbeaumont hbeaumont @ 2005-08-02 15:41 UTC (permalink / raw)
  To: netfilter

Can anyone help me with the proper method to block outgoing requests to 
botnets + irc?

Or point me in the direction of searchable list archives (I could only find 
the non-searchable archives) or other FAQ that answers this?

Problem:

We have servers that could get infected via poorly wrote user scripts. I 
want to prevent these servers from being used as part of botnets or general 
connections to 
IRC (most scripts I run across seem to try to connect to IRC). I want to 
take the best preventative measures I can in case one of the machines would 
become infected
or otherwise compromised.

Also, interested in any other popular method of stopping general outgoing 
DOS attacks (rate limiting UDP perhaps? I'm not real up on the techniques 
used by the DOS'ers).

I'm interested in the recommended rules to add to prevent this type of thing 
should it occur. Thanks.

^ permalink raw reply	[flat|nested] 9+ messages in thread
* RE: blocking irc + botnets
@ 2005-08-02 16:37 Piszcz, Justin
  0 siblings, 0 replies; 9+ messages in thread
From: Piszcz, Justin @ 2005-08-02 16:37 UTC (permalink / raw)
  To: hbeaumont hbeaumont, netfilter

Well to start out, you'd want to block outbound TCP ports 6660-7000,
there are however, some IRC servers that accept connections on weird
ports to bypass firewalls.

-----Original Message-----
From: netfilter-bounces@lists.netfilter.org
[mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of hbeaumont
hbeaumont
Sent: Tuesday, August 02, 2005 11:41 AM
To: netfilter@lists.netfilter.org
Subject: blocking irc + botnets

Can anyone help me with the proper method to block outgoing requests to 
botnets + irc?

Or point me in the direction of searchable list archives (I could only
find 
the non-searchable archives) or other FAQ that answers this?

Problem:

We have servers that could get infected via poorly wrote user scripts. I

want to prevent these servers from being used as part of botnets or
general 
connections to 
IRC (most scripts I run across seem to try to connect to IRC). I want to

take the best preventative measures I can in case one of the machines
would 
become infected
or otherwise compromised.

Also, interested in any other popular method of stopping general
outgoing 
DOS attacks (rate limiting UDP perhaps? I'm not real up on the
techniques 
used by the DOS'ers).

I'm interested in the recommended rules to add to prevent this type of
thing 
should it occur. Thanks.


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2005-08-05  6:26 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-08-02 15:41 blocking irc + botnets hbeaumont hbeaumont
2005-08-02 16:55 ` Daniel Lopes
2005-08-02 18:36   ` R. DuFresne
2005-08-03 16:18 ` Maxime Ducharme
2005-08-04  7:43 ` Jan Engelhardt
2005-08-04 17:04   ` hbeaumont hbeaumont
2005-08-04 21:59     ` curby .
2005-08-05  6:26     ` Jan Engelhardt
  -- strict thread matches above, loose matches on Subject: below --
2005-08-02 16:37 Piszcz, Justin

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.