Hello
This message follows the security alert that we sent you.
Please excuse for the response timedue to the fact that
the problem has touched a very large number of machines.
What is the reason for this warning?
We found abnormal connections from certain IPs connected to
IRC protocols and related to attacks in the network.
After checking we found a very large number of servers
hacked in root with illegal eggdrops and psybnc launched
If your server currently has not been suspended there are
chances that you're not affected by the hack / illegal
use.
How to check?
a) If you do not use IRC and if you not have declared any
IRC protocol in your manager (incoming or outgoing
connection) you must definitely check out your machine is
probably infected with a backdoor.
Check with lsattr /usr/xxx (folder that contains your
binarys) that NO ONE is listed in --ia-- rights.
More help:
OVH : HackedMachineExample
b) if you run your own eggdrop psybnc or something else for
irc ) or if you have a linked your ircd to one of the
blocked IP's and you have correctly reported those
addresses into the manager, you can ignore this warning.
We recommend you any time to verify that your eggdrop,
psybnc etc.. is not hacked.
b1) if you have not yet reported your IRC connections (d)
thank you for doing so.
c) you can connect to an irc:
in this case it is quite possible that this gate is part of
IRC IP's who had the most illegal connections.
These IP are nullrouted.
The abuse @ NOC these IP's have been contacted.
This nullroute will be removed when an agreement between
the NOC and NOC ovh in question have been found.
Sincerely,
Angie
Segnalibri