Re: IRC -> smtp worm?

From: H C (keydet89@yahoo.com)
Date: 12/18/02

  • Next message: Eric Chien: "Re: IRC -> smtp worm?"
    Date: Wed, 18 Dec 2002 08:00:37 -0800 (PST)
    From: H C <keydet89@yahoo.com>
    To: incidents@securityfocus.com
    
    

    > Is anyone aware of some kind of IRC worm that uses
    > SMTP servers to act
    > as a spy client or something like that?

    I'm not sure what you mean by this. After all, why
    would an IRC worm need SMTP capability? If the worm
    causes the compromise system to connect to an IRC
    channel, why would SMTP capability be needed?

    > Not that i consider this a serious issue ( from the
    > server side of
    > course ), but I'm curious on what's causing this
    > behaviour.

    If you really are curious as to what is causing this
    behaviour, I would suggest that you go back to your
    IDS and identify the specific systems from which this
    traffic originates, and then investigate those
    systems. Since you say that this traffic has been
    picked up by your IDS, it's just common sense that the
    sources of the traffic should be investigated.

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: cant send mail to hotmail or yahoo mail
      ... In my little brain, a SMTP client ... I imagine that Yahoo has SMTP servers to accept and ... If Yahoo! ...
      (microsoft.public.dotnet.languages.csharp)
    • [Full-Disclosure] A Report on SPAM Blackholes, Blocking/Filtering, and AOL
      ... For the last month I have purposefully used AOL for SMTP server mail relay ... outbound e-mails have been blocked by blackhole sites in the last month. ... that AOL is getting filtered/blocked in its entirety by many SMTP servers. ...
      (Full-Disclosure)
    • Re: company name change
      ... I'm not sure how your SMTP servers are configured. ... Do you only have 1 Recipient Policy currently? ...
      (microsoft.public.exchange.admin)
    • Re: Error 450 - too many recipient
      ... The only information I have is the response on the connection to smtp service: ... > As I outlined in my prev post, taking less than 100 recipients per message ... The general principle that relaying SMTP servers ... > But I've never seen exchange behaving like you described. ...
      (microsoft.public.exchange2000.protocols)
    • Re: Help setting up two SMTP servers
      ... inbound servers are determined by MX records and their targets - you can point these to the appropriate Exchange/Windows SMTP servers. ...
      (microsoft.public.exchange.setup)