Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

Some annoying bots
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse
Author Message
Jedi
none
none


Joined: 07 Jul 2003
Posts: 26

PostPosted: Nov 15, 2003 11:51am    Post subject: Reply with quote

ed, that script does work with the mods done by skerg as I have it running on a seperate mirc on our network.
I have the mirc in common channels that the drone was going into, and so far to this date, I think it has killed at least 10 of the bots off our network.

Our coder is gonna try to code it into our services also.
Back to top
Terry
none
none


Joined: 17 Jul 2003
Posts: 28

PostPosted: Nov 15, 2003 9:31pm    Post subject: Reply with quote

I would like to take a glance at the code for that bot if you don't mind sharing tiko...
Back to top
Terry
none
none


Joined: 17 Jul 2003
Posts: 28

PostPosted: Nov 15, 2003 9:36pm    Post subject: Reply with quote

Never mind tiko I seen it in your channel topic :wink:
Back to top
tiko
none
none


Joined: 24 Sep 2003
Posts: 49

PostPosted: Nov 15, 2003 10:55pm    Post subject: The bot. Reply with quote

Is right here: http://www.7sinz.net/spambot/spambot.txt

This is just the script, I'm not posting the executable.
Back to top
Guest






PostPosted: Nov 16, 2003 6:31am    Post subject: SecureServ has included a virii def. to ban these bots Reply with quote

Code:
(SNotice) *** Notice -- Client connecting on port 6667: Z|]\GE`G]^ (~MLxzEAI@[...]) [clients]
(SNotice) *** G:Line added for *@[...] on Sun Nov 16 11:28:12 2003 GMT (from SecureServ to expire at Sun Nov 16 12:28:12 2003 GMT: Infected with: WebCamSpam (See http://secure.irc-chat.net/info.php?viri=WebCamSpam for more info))
(SNotice) *** Notice -- Client exiting: Z|]\GE`G]^ (~MLxzEAI@[...]) [User has been banned from LCIRC (Infected with: WebCamSpam (See http://secure.irc-chat.net/info.php?viri=WebCamSpam for more info))]


ect ect..

you can find SecureServ which is part of the NeoStats package at: http://www.neostats.net[/code]
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 16, 2003 12:28pm    Post subject: Reply with quote

Appears to be two variants of this. One uses a domain name in the real name field - .com .org .net .ca are the ones seen so far, some are real, most are bogus.

The other variant uses a varying length real name field, all alpha, sometimes mixed-case.

I've been just setting shuns on them whenever they appear, timed to expire in three hours. There aren't enough hitting simultaneously to load the machine.
Back to top
Jason
SearchIRC Developer
SearchIRC Developer


Joined: 03 May 2003
Posts: 1484
Location: Tampa, FL

PostPosted: Nov 16, 2003 12:31pm    Post subject: Reply with quote

Anyone logging the websites that are being spammed, and contacting providers about getting them shut down?
Back to top
tiko
none
none


Joined: 24 Sep 2003
Posts: 49

PostPosted: Nov 16, 2003 3:43pm    Post subject: Reply with quote

Hey Jason,

have a look at the script. The addy it spams is actually the infected machine. http://my.real.host.com:random port/me.mpg
Back to top
Jason
SearchIRC Developer
SearchIRC Developer


Joined: 03 May 2003
Posts: 1484
Location: Tampa, FL

PostPosted: Nov 16, 2003 7:15pm    Post subject: Reply with quote

Ah, I see. For some reason I was under the impression that the script was being run by a spammer to get users to go to a spam website. It looks like this script is basically a typical IRC trojan/virus that tries to spread itself to others.
Back to top
RejiMC
Guest





PostPosted: Nov 17, 2003 1:41am    Post subject: Reply with quote

Using SecureServ (from http://www.neostats.net) helps akill these bots automatically. Its working fine on our servers.
Back to top
tigger
Guest





PostPosted: Nov 17, 2003 5:39am    Post subject: How to get rid of the bots Reply with quote

Hey the only way to get rid of them to to change your IP Address you can set up neostats to Gline them but the only sure cure for right now is to change the IP also you might want to change the alias for you IRCD as well since in the .ini file the bot uses to connect has your irc.yournetwork.net and your IP in its file we had the same problem with the bots as you are haveing we changed our domain alias and our IP and they are gone .... if you need any more info stop by my server irc.nothingbutstyle.net or give me an email admin@nothingbutstyle.net Smile
Tigger
Back to top
U
Eleet
Eleet


Joined: 18 Jun 2003
Posts: 521
Location: IRC

PostPosted: Nov 17, 2003 11:13am    Post subject: Reply with quote

BTW, I believe the server list for these didn't come from any IRC site-I think its the current mIRC servers.ini, which means this thing was unleashed very recently, as I recall a new servers.ini coming out right before the new release of mIRC.

These seem to be increasing also. Besides the script, I think awareness needs to be raised again to all users to NOT click any url they recieve-because if the number of these is going up, that means people are getting infected by clicking.

Maybe mIRC needs to come up with something that when a url is posted into a channel, it gets munged, or something similar, and make that warning box that pops up come up every time-not have the ability to turn it off, so maybe people will think before clicking. I have a feeling most people turned it off the first time they saw it and are now forgetting about the warning it provided.

These things will keep getting made and posted as long as people continue to click on anything they get Smile
Back to top
tiko
none
none


Joined: 24 Sep 2003
Posts: 49

PostPosted: Nov 17, 2003 11:53am    Post subject: Reply with quote

I disagree. mIRC doesn't add networks with >300 users to its servers.ini, and there are several listed with less than 100, included mine.
Back to top
Mary
SearchIRC Admin
SearchIRC Admin


Joined: 03 May 2003
Posts: 696

PostPosted: Nov 17, 2003 1:41pm    Post subject: Reply with quote

tigger, that also keeps users off your network - and its only good until the next servers.ini list is out. Then your information is updated and you are open to the abuse du jour.
Back to top
Michael
none
none


Joined: 18 May 2003
Posts: 48

PostPosted: Nov 17, 2003 2:35pm    Post subject: Reply with quote

Plus, as I replied to him, changing a domain isn't exactly free Wink
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse All times are GMT - 6 Hours
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
Page 3 of 8

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer