Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

Preventing/Stopping Botnet Attacks

 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse
Author Message
ConflictTheory
none
none


Joined: 04 Nov 2008
Posts: 7

PostPosted: Nov 04, 2008 11:34am    Post subject: Preventing/Stopping Botnet Attacks Reply with quote

Hello,

I am an admin of a small network. Recently the staff voted to let a member go because of his failure to come to staff meetings, his bad judgment, and his bad attitude. This individual before hand had been a friend of mine for many years. But now, he insists on flooding our network with a massive amount of bots, that spit out random curse words and vulgarities. I was wondering if anyone knew of a good way to prevent this from happening? All he has done so far is flood our channel to the point he pings out, just the massive amount of joins/parts & text from these 30 or so bots is rather annoying. but I would like to prevent this before it starts affecting our userbase.

Thanks for any insight Smile
Back to top
zeke
Idler
Idler


Joined: 04 Oct 2003
Posts: 325

PostPosted: Nov 04, 2008 12:13pm    Post subject: Reply with quote

A proxy scanner (such as BOPM)
G:lines

Depending on your IRCd and Services packages you may be able to perform other checks on users connecting.

NeoStats with SecureServ for example may catch some things, IRC Defender also.

UnrealIRCd and others support regular expression bans (spamfilters within Unreal) - if the flooding clients match a pattern that isn't easily banned as a static identd/host, you can use a regular expression ban against any combination of nick, ident, hostname, and real name - the UnrealIRCd forums will often help fairly quickly with regular expressions for this purpose.
Back to top
ConflictTheory
none
none


Joined: 04 Nov 2008
Posts: 7

PostPosted: Nov 04, 2008 12:19pm    Post subject: Reply with quote

zeke...

Thank you for the suggestions...

We have Neostats with ConnectServ & OPSB

I'm also looking into a few modules for our services and I'll look at IRC Defender too...

Thanks Smile
Back to top
Katlyn
Newbie
Newbie


Joined: 30 Sep 2006
Posts: 54

PostPosted: Nov 04, 2008 3:13pm    Post subject: Reply with quote

If they are open proxies then add DroneBL and SwiftBL to your open proxy scanner and I guarentee the majority of the bots will be stopped (if not all).

Edit:

Also if you use Anope then I'll be happy to provide you with a TRACE module similar to the one integrated into srvx/x3 which makes removing the bots effortless. Just send me a PM on here.

- Katlyn
Back to top
youngblood
Newbie
Newbie


Joined: 17 Apr 2008
Posts: 66

PostPosted: Nov 04, 2008 3:28pm    Post subject: re botnets Reply with quote

why not trying to firewalling the country hes from this guy i used to admin for did that and it stopped them totally
and what he is doing is very childish acts sorry hes doing this

youngblood
Back to top
ConflictTheory
none
none


Joined: 04 Nov 2008
Posts: 7

PostPosted: Nov 04, 2008 9:14pm    Post subject: Reply with quote

Katlyn wrote:
If they are open proxies then add
DroneBL and SwiftBL to your open proxy scanner and I guarentee the majority of the bots will be stopped (if not all).

Edit:

Also if you use Anope then I'll be happy to provide you with a TRACE module similar to the one integrated into srvx/x3 which makes removing the bots effortless. Just send me a PM on here.

- Katlyn


It wont let me pm you since in still a "new user" Sad
Back to top
mouselike
Idler
Idler


Joined: 09 Dec 2003
Posts: 271

PostPosted: Nov 05, 2008 4:20am    Post subject: Reply with quote

since most bots like this dont require or use ident, just set your server to require ident or k/gline ~*@*.

If you use ircu you can use the challenge auth iauth or something i think its called where you have to send a random reply back to the server before it lets you continue onwards.
Back to top
ConflictTheory
none
none


Joined: 04 Nov 2008
Posts: 7

PostPosted: Nov 05, 2008 8:43am    Post subject: Reply with quote

not quiet sure how to set that up on unreal... :/
Back to top
Katlyn
Newbie
Newbie


Joined: 30 Sep 2006
Posts: 54

PostPosted: Nov 05, 2008 12:44pm    Post subject: Reply with quote

ConflictTheory wrote:
Katlyn wrote:
If they are open proxies then add
DroneBL and SwiftBL to your open proxy scanner and I guarentee the majority of the bots will be stopped (if not all).

Edit:

Also if you use Anope then I'll be happy to provide you with a TRACE module similar to the one integrated into srvx/x3 which makes removing the bots effortless. Just send me a PM on here.

- Katlyn


It wont let me pm you since in still a "new user" Sad


I've sent you a PM (i think) - if you haven't got it just let me know on here.
Back to top
ConflictTheory
none
none


Joined: 04 Nov 2008
Posts: 7

PostPosted: Nov 05, 2008 1:21pm    Post subject: Reply with quote

I got it, thank you
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse All times are GMT - 6 Hours
Page 1 of 1

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer