Security Basics mailing list archives

Re: Increase in traffic on port 20480 and 6667


From: Johan De Meersman <johan () ops skynet be>
Date: Fri, 18 Oct 2002 14:12:58 +0200

KoRe MeLtDoWn wrote:

Be informed that 6667 is also one of the most common ports for IRC
servers to run on....

From: "Kip Sr." <kipsr1 () yahoo com>
to port 6667 (internal desktops). Both ports are
commonly used by trojan horse programs. Has anyone

Both right, and more: lots of trojans (zombies, backdoors) will use this
port because they (try to) connect to a private channel on a given irc
server, where they hang around waiting for command triggers from the
script kiddie that launched them.

One might foil a lot of backdooring crap by restricting outgoing traffic
for irc and such stuff to servers one actually needs. Not feasible for
everything, but certainly for irc, news and the like, where content is
propagated between servers.

-- 
Public GPG key at blackhole.pca.dfn.de .

Attachment: _bin
Description:


Current thread: