Full Disclosure mailing list archives
Re: Scan for IRC
From: Harry Hoffman <hhoffman () ip-solutions net>
Date: Sat, 22 Jan 2005 08:55:45 -0500
Use ngrep to look for signs of irc (i.e. PRIVMSG) instead of just looking for the ports irc (ususally, but not always) runs on.
something like: "ngrep -qitd eth0 'privmsg'" will probably get you much better results.
HTH, Harry ALD, Aditya, Aditya Lalit Deshmukh wrote:
How do u know that you are looking for the irc traffic ? Somewhere you must have see connections going out to some host or some connection attempts. You could always try sniffing using that ip address on all ports if you have setup everthing else correctly...How ever if something is not setup correctly then you would have trouble shoot this. Maybe posting some more info will help us all diagnose this foryou and help u out - maybe offlist ?-aditya-----Original Message-----From: full-disclosure-bounces () lists netsys com [mailto:full-disclosure-bounces () lists netsys com] On Behalf Of RandallMSent: Saturday, January 22, 2005 05:04 AM To: full-disclosure () lists netsys com Subject: [Full-disclosure] Scan for IRC I am so sorry for interrupting the list. I'm trying to pick up IRC communications on the network. I've made some filters for Ethereal andObserver but can't seem to pick it up. I'm doing something wrong. Used the 6668-6669 ports. Any help?thank you Randall M _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html________________________________________________________________________ Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Scan for IRC RandallM (Jan 21)
- Re: Scan for IRC Athanasius (Jan 21)
- Re: Scan for IRC Oliver Leitner (Jan 21)
- RE: Scan for IRC Nikolay Baramov (Jan 21)
- Re: RE: Scan for IRC Frank Knobbe (Jan 21)
- RE: Scan for IRC Nikolay Baramov (Jan 21)
- Re: Scan for IRC Kevin (Jan 21)
- Re: Scan for IRC Jon Hart (Jan 21)
- Re: Scan for IRC Paul Schmehl (Jan 21)
- RE: Scan for IRC ALD, Aditya, Aditya Lalit Deshmukh (Jan 22)
- Re: Scan for IRC Harry Hoffman (Jan 22)