Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

mo' bots - not quite on the fizzer scale, but close

 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse
Author Message
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 17, 2003 11:09am    Post subject: mo' bots - not quite on the fizzer scale, but close Reply with quote

Started 11/17/03, about 1800 pacific, about 50 an hour, plus or minus.

Only signatures identified so far is that they're joining one of 8 channel names:

#bccbots
#digital-playground
#divxstation
#ds-xdcc
#ftps
#globalwatchzone
#ixdcc
#zeta

Most heavily hit is #ds-xdcc, only output from any of them so far has been on join 'password' in a notice, and '$#$@!@#' in notice from a couple when they were deopped.

Anyone but bdsm-net getting hit?
Back to top
U
Eleet
Eleet


Joined: 18 Jun 2003
Posts: 521
Location: IRC

PostPosted: Nov 17, 2003 11:16am    Post subject: Reply with quote

I haven't seen these yet, and usually whenever there is something like this my network tends to get hit too (well, they all do, but on a smaller network you notice them alot quicker!)
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 17, 2003 12:06pm    Post subject: Reply with quote

U wrote:
I haven't seen these yet, and usually whenever there is something like this my network tends to get hit too (well, they all do, but on a smaller network you notice them alot quicker!)


Yeah, that it is.
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 18, 2003 2:59pm    Post subject: Reply with quote

new info, appears that the behavior is consistent with symantec's writeup of W32.HLLW.Bereb - or a derivative thereof.

Fizzer all over again.
Back to top
U
Eleet
Eleet


Joined: 18 Jun 2003
Posts: 521
Location: IRC

PostPosted: Nov 18, 2003 6:04pm    Post subject: Reply with quote

Actually its the same continued idiocy-people continue to accept files or open emails with attachments from people they don't know.

People just don't learn.
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 18, 2003 6:47pm    Post subject: Reply with quote

idiocy on the part of the users, certainly - but there's more to the deal.

Turns out that bdsm-net wasn't the target. Someone else was the target - and I guess to stay within the guidelines here I'll have to keep the name to myself - at least openly.

But when *they* got hit, they decided that it wasn't worth their trouble to deal with the attack. Instead they pointed irc.......net in their dns server to another irc system, one that they had no connection whatever with.

Naturally that particular server choked, and managed to find out where the choke was coming from. So instead of null-routing their irc.......net dns entry, they pointed it at us.

Really, really nice people out there in joisey.
Back to top
Jason
SearchIRC Developer
SearchIRC Developer


Joined: 03 May 2003
Posts: 1484
Location: Tampa, FL

PostPosted: Nov 18, 2003 8:26pm    Post subject: Reply with quote

Howard,

We'd like to know the name of the network.

BTW Network names are allowed to be mentioned, just not in the SUBJECT of an initial post on all forums except 'Network announcements'.

I hope that makes sense :)
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 18, 2003 9:16pm    Post subject: Reply with quote

weaklinks.net

they nulled out the dns entry, but managed to pump 2gb of meaningless traffic into me before they did.

Got *no* idea of what they managed to pound into the other victim.

Admin said 'I don't control it' first, then 'they're just bottlers, they are valid irc clients'

Yeah, right. Like I'm going to put up with 10,000 drones on a purpose-built net. Got no problem at all with a lot of real people coming in to pursue an interest - that's what the place is for. But maybe it's time to start thinking about registering folks first.
Back to top
Jason
SearchIRC Developer
SearchIRC Developer


Joined: 03 May 2003
Posts: 1484
Location: Tampa, FL

PostPosted: Nov 18, 2003 9:20pm    Post subject: Reply with quote

Ah, thats funny.

Our software detected a network merge (e.g; your channel list matched theirs), and it attributed Weaklinks to having merged with your network.

In fact, all that happened was they routed their traffic to you.

Either way, we do not list networks that point their dns to other networks, simply because it screws up the channel listings.

I'll go ahead and update the weaklinks info (so it doesn't say it merged with bdsm-net)

http://searchirc.com/network/WeakLinks
Back to top
Howard
none
none


Joined: 16 Nov 2003
Posts: 34

PostPosted: Nov 19, 2003 7:24am    Post subject: Reply with quote

Jason wrote:
Ah, thats funny.

Our software detected a network merge (e.g; your channel list matched theirs), and it attributed Weaklinks to having merged with your network.


<<several lines of text deleted before submission, indicating that some folks have ancestry and personal habits that are rather remarkable, expressed in terms that take many years of arduous sea duty to learn >>

Suffice to say that there isn't, and *won't* be any kind of a connection between bdsm-net and weaklinks, as long as I or any of the current admin crew at bdsm-net have anything to do with the operation.

'Nuff said.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse All times are GMT - 6 Hours
Page 1 of 1

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer