|
|
| Author |
Message |
Jedi none

Joined: 07 Jul 2003 Posts: 26
|
Posted: Nov 15, 2003 11:51am Post subject: |
|
|
ed, that script does work with the mods done by skerg as I have it running on a seperate mirc on our network.
I have the mirc in common channels that the drone was going into, and so far to this date, I think it has killed at least 10 of the bots off our network.
Our coder is gonna try to code it into our services also. |
|
| Back to top |
|
 |
Terry none

Joined: 17 Jul 2003 Posts: 28
|
Posted: Nov 15, 2003 9:31pm Post subject: |
|
|
| I would like to take a glance at the code for that bot if you don't mind sharing tiko... |
|
| Back to top |
|
 |
Terry none

Joined: 17 Jul 2003 Posts: 28
|
Posted: Nov 15, 2003 9:36pm Post subject: |
|
|
| Never mind tiko I seen it in your channel topic :wink: |
|
| Back to top |
|
 |
tiko none

Joined: 24 Sep 2003 Posts: 49
|
|
| Back to top |
|
 |
Guest
|
Posted: Nov 16, 2003 6:31am Post subject: SecureServ has included a virii def. to ban these bots |
|
|
| Code: | (SNotice) *** Notice -- Client connecting on port 6667: Z|]\GE`G]^ (~MLxzEAI@[...]) [clients]
(SNotice) *** G:Line added for *@[...] on Sun Nov 16 11:28:12 2003 GMT (from SecureServ to expire at Sun Nov 16 12:28:12 2003 GMT: Infected with: WebCamSpam (See http://secure.irc-chat.net/info.php?viri=WebCamSpam for more info))
(SNotice) *** Notice -- Client exiting: Z|]\GE`G]^ (~MLxzEAI@[...]) [User has been banned from LCIRC (Infected with: WebCamSpam (See http://secure.irc-chat.net/info.php?viri=WebCamSpam for more info))] |
ect ect..
you can find SecureServ which is part of the NeoStats package at: http://www.neostats.net[/code] |
|
| Back to top |
|
 |
Howard none

Joined: 16 Nov 2003 Posts: 34
|
Posted: Nov 16, 2003 12:28pm Post subject: |
|
|
Appears to be two variants of this. One uses a domain name in the real name field - .com .org .net .ca are the ones seen so far, some are real, most are bogus.
The other variant uses a varying length real name field, all alpha, sometimes mixed-case.
I've been just setting shuns on them whenever they appear, timed to expire in three hours. There aren't enough hitting simultaneously to load the machine. |
|
| Back to top |
|
 |
Jason SearchIRC Developer

Joined: 03 May 2003 Posts: 1486 Location: Tampa, FL
|
Posted: Nov 16, 2003 12:31pm Post subject: |
|
|
| Anyone logging the websites that are being spammed, and contacting providers about getting them shut down? |
|
| Back to top |
|
 |
tiko none

Joined: 24 Sep 2003 Posts: 49
|
Posted: Nov 16, 2003 3:43pm Post subject: |
|
|
Hey Jason,
have a look at the script. The addy it spams is actually the infected machine. http://my.real.host.com:random port/me.mpg |
|
| Back to top |
|
 |
Jason SearchIRC Developer

Joined: 03 May 2003 Posts: 1486 Location: Tampa, FL
|
Posted: Nov 16, 2003 7:15pm Post subject: |
|
|
| Ah, I see. For some reason I was under the impression that the script was being run by a spammer to get users to go to a spam website. It looks like this script is basically a typical IRC trojan/virus that tries to spread itself to others. |
|
| Back to top |
|
 |
RejiMC Guest
|
Posted: Nov 17, 2003 1:41am Post subject: |
|
|
| Using SecureServ (from http://www.neostats.net) helps akill these bots automatically. Its working fine on our servers. |
|
| Back to top |
|
 |
tigger Guest
|
Posted: Nov 17, 2003 5:39am Post subject: How to get rid of the bots |
|
|
Hey the only way to get rid of them to to change your IP Address you can set up neostats to Gline them but the only sure cure for right now is to change the IP also you might want to change the alias for you IRCD as well since in the .ini file the bot uses to connect has your irc.yournetwork.net and your IP in its file we had the same problem with the bots as you are haveing we changed our domain alias and our IP and they are gone .... if you need any more info stop by my server irc.nothingbutstyle.net or give me an email admin@nothingbutstyle.net
Tigger |
|
| Back to top |
|
 |
U Eleet

Joined: 18 Jun 2003 Posts: 521 Location: IRC
|
Posted: Nov 17, 2003 11:13am Post subject: |
|
|
BTW, I believe the server list for these didn't come from any IRC site-I think its the current mIRC servers.ini, which means this thing was unleashed very recently, as I recall a new servers.ini coming out right before the new release of mIRC.
These seem to be increasing also. Besides the script, I think awareness needs to be raised again to all users to NOT click any url they recieve-because if the number of these is going up, that means people are getting infected by clicking.
Maybe mIRC needs to come up with something that when a url is posted into a channel, it gets munged, or something similar, and make that warning box that pops up come up every time-not have the ability to turn it off, so maybe people will think before clicking. I have a feeling most people turned it off the first time they saw it and are now forgetting about the warning it provided.
These things will keep getting made and posted as long as people continue to click on anything they get  |
|
| Back to top |
|
 |
tiko none

Joined: 24 Sep 2003 Posts: 49
|
Posted: Nov 17, 2003 11:53am Post subject: |
|
|
| I disagree. mIRC doesn't add networks with >300 users to its servers.ini, and there are several listed with less than 100, included mine. |
|
| Back to top |
|
 |
Mary SearchIRC Admin

Joined: 03 May 2003 Posts: 696
|
Posted: Nov 17, 2003 1:41pm Post subject: |
|
|
| tigger, that also keeps users off your network - and its only good until the next servers.ini list is out. Then your information is updated and you are open to the abuse du jour. |
|
| Back to top |
|
 |
Michael none

Joined: 18 May 2003 Posts: 48
|
Posted: Nov 17, 2003 2:35pm Post subject: |
|
|
Plus, as I replied to him, changing a domain isn't exactly free  |
|
| Back to top |
|
 |
|