irc.chatster.org

Due to the overwhelming abuse of misconfigured HTTP, SOCK, and WINGATE proxies being exploited, it's Chatster IRC Network Policy to scan all users for these exploitable open ports upon connection to any Chatster.org IRC Server.

This check is ONLY DONE if a user attempts to establish a connection to any IRC server of *.chatster.org including connections using our web java chat program.   These are not Denial of Service attacks or hack attempts, but instead are part of an effort to help us identify and properly deal with the growing problem of insecure Wingate, Socks, and Proxy Servers and their abuse on IRC networks.   We recommend window users to visit Shields Up! Internet Connection Security by Gibson Research Corporation to quickly check the security of your computer's connection to the Internet.

If you received a "port scan/connection attempt" on your system
Please continue to read below for further information.

Improperly configured Wingate and Socks Proxy server abuse has become a huge problem for IRC networks. Checking users as they attempt to connect to a IRC server is becoming a more common practice as more value added services such as IRC networks are seeing increasing levels of virtually anonymous abuse of their resources from these servers.

Many common utilities like ZoneAlarm and Tiny Personal Firewall throw alerts if they catch checks aimed at ports using Wingate (port 23), SOCKS4/5 (port 1080), and HTTP proxy (ports 3128 and 8080).  Usually these probes are happening because you have connected to our IRC network where our services bot tries to connect to these ports on your computer. The reason our services are doing this is to check if you have misconfigured open ports. This type of scan should not be considered an attack on your system from us, and please be aware that this sort of connection to your system will probably become more common in the future if you use services such as free IRC networks, game servers, etc...

If you do not desire this type of check to occur, then simply do not connect to any chatster.org servers in the future.  This check ONLY occurs when a person attempts to establish a connection to a chatster.org IRC server.

We urge all users to learn as much about any monitoring software package that you have installed, such as ZoneAlarm or Tiny Personal Firewall, and to thoroughly read any and all help files that came with the program.  Frequently check the web site of your monitoring software as they usually post updates and tips. If you do not have a firewall for your PC, We recommenad using ZoneAlarm to protect your computer from abuse.   ZoneAlarm is user friendly and free. (There is a "Professional" version of ZoneAlarm that can be purchase as well.)

Listed below is additional information we found on the internet which will assist you further in securing your software:

Fixing a Wingate server

Upgrade your Wingate server if version prior to 2.1 : click here
Get help about Wingate at www.practicallynetworked.com.


Fixing a Socks 4/5 server

The following are a few URL which could help you fix your misconfigured proxy server on a Windows machine :
Socks Proxy server : click here
Upgrade and get help about your winproxy at : www.winproxy.com
Upgrade your sygate server at : www.sygate.com


Fixing a Squid server

Get help for Squid ACLs at : http://www.squid-cache.org/Doc/FAQ/FAQ-10.html#ss10.2
Get detailed help at : http://www.documents.cyberabuse.org/?page=vulnerabilities&doc=1
Upgrade your Squid 1.x server at : www.squid-cache.org


Fixing a HTTP proxy server

Vulnerable proxy servers can be of all types and brands. If your proxy server is not supported anymore and you are not sure about your configuration, firewall it so only your LAN can use it.
Get help about WinRoute at www.kerio.com. They have a manual in adobe format found under downloads/support.
Get detailed help about CacheFlow at : http://www.documents.cyberabuse.org/?page=vulnerabilities&doc=2



NOTICE: IRC is an unmoderated international medium, and the number of users on IRC servers are in the thousands.
BMC, Inc. or it's associates will not be held liable for any operation, command, language,
or conduct from any user or server even upon prior notice.
(c) 2001-2008, BMC Inc., All Rights Reserved.