|
|
| Author |
Message |
theEd Newbie

Joined: 15 Mar 2004 Posts: 75 Location: New Zealand
|
Posted: Jul 09, 2008 3:41pm Post subject: |
|
|
Willaim, they do certainly seem to be reusing names. That said I'd say the only way we could make a name list would be to just keep an eye out for them and post here if there's a new name used.
As far as zeke and I can tell so far, they're not doing anything. That's what makes it so strange - they only seem to talk if you talk to them via PM, and even then they never advertised anything. Whatsmore, as they are only there for two minutes (never shorter or longer), it doesn't give them too much time if they're only spamming via PM to people who initiate a convo with them.
I also haven't seen them get killed by spamfilters or anything on any of the server I've seen them on, which would also suggest that they're not spamming.
maddog906, most of what you posted is irrelevant. The bots are not posting URLs, are not using random-looking nicks or idents, and they aren't spamming in PM.
| Jobe wrote: | | True, however, you can match them on nick = ident, gecos = ctcp version, nick != gecos and host = *.fr |
Best suggestion I've seen so far! |
|
| Back to top |
|
 |
greg27 Lurker

Joined: 07 Oct 2006 Posts: 178 Location: Australia
|
Posted: Jul 09, 2008 11:48pm Post subject: |
|
|
| blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s |
|
| Back to top |
|
 |
maddog906 Lurker

Joined: 08 Mar 2005 Posts: 132 Location: uk
|
Posted: Jul 10, 2008 2:31am Post subject: true |
|
|
[05:47am] [ConnectServ] SIGNON user: cybergirl
[05:47am] [ConnectServ] SIGNOFF user: cybergirl (cybergirl@*.wanadoo.fr 35 F ) at (mynetwork Z:lined (SomeLameScript contains backdoors),
While been on irc 8 years I have learnt that botz like this always come back with a hidden agenda, you let them in once next time bang your world is turned upside down.
Prevention is always better than a cure; it really makes you sleep better at night.
all my infomation is only advice for things to come,this might be just a chat bot,what about the next genaration of botz? |
|
| Back to top |
|
 |
maddog906 Lurker

Joined: 08 Mar 2005 Posts: 132 Location: uk
|
Posted: Jul 11, 2008 1:38am Post subject: i was hoping some one |
|
|
| Jobe wrote: | | theEd wrote: | | maddog906, the user/nick, realname and ctcp replies change |
True, however, you can match them on nick = ident, gecos = ctcp version, nick != gecos and host = *.fr |
spamfilter is not just for spam etc http:// or pm spam it does much more,
as Jobe says:
/spamfilter add u gzline 1h Channel_Flooder !~?[a-z][0-9]{1,4}@[^:]+:[a-z]{9}
or
/spamfilter add u gzline 24h Sex_BotZ ^(?-i)[A-Z](?i)[a-z]*\^[0-9]{2}!
you can macth is to any nick/any ip/any place. |
|
| Back to top |
|
 |
theEd Newbie

Joined: 15 Mar 2004 Posts: 75 Location: New Zealand
|
Posted: Jul 11, 2008 7:17am Post subject: |
|
|
| greg27 wrote: | | blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s |
Yeah. What's the bet they're designed to confuse admins like us  |
|
| Back to top |
|
 |
zeke Idler

Joined: 04 Oct 2003 Posts: 325
|
Posted: Jul 12, 2008 12:16am Post subject: |
|
|
So, shall we start a namelist?
[18:10:32] <Global> LOGUSERS: [bang!] (mbullegg@[bang!] => *-DB577F91.rev.numericable.fr) (h 22 oke) [[bang!]] connected to the network (kings.il.us.*.com).
[bang!]
/* Edit */
You know, I've just realised - the host is changing, however they're all from the same IP address - ***.
| Code: |
[May 02 23:36:53 2008] LOGUSERS: *** (anna30@***.noos.fr => *-B0291569.dhcp212-198-248.noos.fr) (30 F ..) [***] connected to the network (romans.il.us.*.com).
[May 05 01:53:40 2008] LOGUSERS: *** (paula35@***.noos.fr => *-B0291569.dhcp212-198-248.noos.fr) (35 F) [***] connected to the network (romans.il.us.*.com).
[Jul 07 22:12:18 2008] LOGUSERS: *** (mbullegg@*** => *-DB577F91.rev.numericable.fr) (h 22 oke) [***] connected to the network (israel.il.us.*.com).
[Jul 07 22:12:19 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) left the network (israel.il.us.*.com).
[Jul 10 01:57:22 2008] LOGUSERS: *** (clochette@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (30 F) [***] connected to the network (israel.il.us.*.com).
[Jul 10 01:57:22 2008] LOGUSERS: *** (clochette@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (30 F) left the network (israel.il.us.*.com).
[Jul 12 02:10:29 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) [***] connected to the network (kings.il.us.*.com).
[Jul 12 02:10:30 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) left the network (kings.il.us.*.com).
|
/* Edit 2 */
OK...searched logs even more, there are a couple other addresses. When I'm done dealing with another issue I missed in my downtime a couple months ago, I'll go through again and find some more names, IP's and hosts... |
|
| Back to top |
|
 |
mouselike Idler

Joined: 09 Dec 2003 Posts: 271
|
Posted: Jul 12, 2008 2:00am Post subject: |
|
|
| theEd wrote: | | greg27 wrote: | | blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s |
Yeah. What's the bet they're designed to confuse admins like us  |
We use to get a lot of these on our network, they are spider bots. they fish from sites like g**glom for the possibility of filesharing bots on your network.
They maybe some other bots, but they look very familiar to what we had and just keep banning them is the only way around these. |
|
| Back to top |
|
 |
maddog906 Lurker

Joined: 08 Mar 2005 Posts: 132 Location: uk
|
Posted: Jul 12, 2008 7:56am Post subject: just makes you think |
|
|
| Is it one more move, from RIAA /media defender and all the other anti-file-sharing and anti p2p, what this world coming too? Gee you will find some one else hand wipe ya as (*) before you do and insert a tracking device |
|
| Back to top |
|
 |
phrozen77 Newbie

Joined: 13 Jul 2004 Posts: 86 Location: There!! A 3-headed monkey, right behind you!
|
Posted: Jul 15, 2008 2:33am Post subject: |
|
|
[bang!]
Thats the few that we had yesterday evening, connecting, sitting there for a while and disconnecting again.
Wonder what theyre up to.
And no, the both hosts i've seen them connect from don't resolve to the same IP, infact they even seem to be 2 seperate ISPs.
[bang!] has address [bang!]
[bang!] has address [bang!] |
|
| Back to top |
|
 |
PingBad Guru

Joined: 05 Feb 2005 Posts: 2096 Location: New Zealand
|
Posted: Jul 15, 2008 6:19am Post subject: |
|
|
| zeke wrote: | | So, shall we start a namelist? | Let's not.
I hate to be the hard-ass people, but word from the dude upstairs is that mentioning IP addresses and the like falls under naming names, sorry  |
|
| Back to top |
|
 |
dv8-123 none

Joined: 16 Jul 2008 Posts: 1 Location: Liverpool Uk
|
Posted: Jul 16, 2008 2:50pm Post subject: |
|
|
To be honest, Just look out for the rev.numericable.fr host mask ...
They never stick to the same channels, I have seen them in a number of them, I started doing a whois when i saw them join, now I just kill and make sure that some form of Gline is in place. |
|
| Back to top |
|
 |
Strawberry_Kittens none

Joined: 28 Jun 2008 Posts: 5
|
Posted: Jul 26, 2008 4:00pm Post subject: |
|
|
Here are a couple of regexes that stop bots like that. Worked perfectly on my network.
| Code: |
^([a-zA-Z0-9]+)!([a-z0-9]+)@[^:]+:h \d\d
^([a-zA-Z0-9]+)!([a-z0-9]+)@[^:]+:\d\d F
|
|
|
| Back to top |
|
 |
EcKstasy Lurker

Joined: 23 May 2008 Posts: 149 Location: Scotland
|
Posted: Jul 29, 2008 1:41pm Post subject: CamBots |
|
|
| Yup,Those are called CamBots,They spam the network's users with PM's asking the users to go to sites where they can see the *real* people on cam (>>porn),Beware of those and often try to add a spamfilter for sandra_f as I've seen that one a few times, |
|
| Back to top |
|
 |
|