Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

weird bots
Goto page Previous  1, 2
 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Help
Author Message
theEd
Newbie
Newbie


Joined: 15 Mar 2004
Posts: 75
Location: New Zealand

PostPosted: Jul 09, 2008 3:41pm    Post subject: Reply with quote

Willaim, they do certainly seem to be reusing names. That said I'd say the only way we could make a name list would be to just keep an eye out for them and post here if there's a new name used.

As far as zeke and I can tell so far, they're not doing anything. That's what makes it so strange - they only seem to talk if you talk to them via PM, and even then they never advertised anything. Whatsmore, as they are only there for two minutes (never shorter or longer), it doesn't give them too much time if they're only spamming via PM to people who initiate a convo with them.

I also haven't seen them get killed by spamfilters or anything on any of the server I've seen them on, which would also suggest that they're not spamming.

maddog906, most of what you posted is irrelevant. The bots are not posting URLs, are not using random-looking nicks or idents, and they aren't spamming in PM.

Jobe wrote:
True, however, you can match them on nick = ident, gecos = ctcp version, nick != gecos and host = *.fr


Best suggestion I've seen so far!
Back to top
greg27
Lurker
Lurker


Joined: 07 Oct 2006
Posts: 159
Location: Australia

PostPosted: Jul 09, 2008 11:48pm    Post subject: Reply with quote

blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s
Back to top
maddog906
Lurker
Lurker


Joined: 08 Mar 2005
Posts: 131
Location: uk

PostPosted: Jul 10, 2008 2:31am    Post subject: true Reply with quote

[05:47am] [ConnectServ] SIGNON user: cybergirl
[05:47am] [ConnectServ] SIGNOFF user: cybergirl (cybergirl@*.wanadoo.fr 35 F ) at (mynetwork Z:lined (SomeLameScript contains backdoors),
While been on irc 8 years I have learnt that botz like this always come back with a hidden agenda, you let them in once next time bang your world is turned upside down.
Prevention is always better than a cure; it really makes you sleep better at night.
all my infomation is only advice for things to come,this might be just a chat bot,what about the next genaration of botz?
Back to top
maddog906
Lurker
Lurker


Joined: 08 Mar 2005
Posts: 131
Location: uk

PostPosted: Jul 11, 2008 1:38am    Post subject: i was hoping some one Reply with quote

Jobe wrote:
theEd wrote:
maddog906, the user/nick, realname and ctcp replies change

True, however, you can match them on nick = ident, gecos = ctcp version, nick != gecos and host = *.fr


spamfilter is not just for spam etc http:// or pm spam it does much more,
as Jobe says:
/spamfilter add u gzline 1h Channel_Flooder !~?[a-z][0-9]{1,4}@[^:]+:[a-z]{9}
or
/spamfilter add u gzline 24h Sex_BotZ ^(?-i)[A-Z](?i)[a-z]*\^[0-9]{2}!
you can macth is to any nick/any ip/any place.
Back to top
theEd
Newbie
Newbie


Joined: 15 Mar 2004
Posts: 75
Location: New Zealand

PostPosted: Jul 11, 2008 7:17am    Post subject: Reply with quote

greg27 wrote:
blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s


Yeah. What's the bet they're designed to confuse admins like us Razz
Back to top
zeke
Idler
Idler


Joined: 04 Oct 2003
Posts: 321

PostPosted: Jul 12, 2008 12:16am    Post subject: Reply with quote

So, shall we start a namelist?

[18:10:32] <Global> LOGUSERS: [bang!] (mbullegg@[bang!] => *-DB577F91.rev.numericable.fr) (h 22 oke) [[bang!]] connected to the network (kings.il.us.*.com).

[bang!]

/* Edit */
You know, I've just realised - the host is changing, however they're all from the same IP address - ***.

Code:

[May 02 23:36:53 2008] LOGUSERS: *** (anna30@***.noos.fr => *-B0291569.dhcp212-198-248.noos.fr) (30 F ..) [***] connected to the network (romans.il.us.*.com).
[May 05 01:53:40 2008] LOGUSERS: *** (paula35@***.noos.fr => *-B0291569.dhcp212-198-248.noos.fr) (35 F) [***] connected to the network (romans.il.us.*.com).
[Jul 07 22:12:18 2008] LOGUSERS: *** (mbullegg@*** => *-DB577F91.rev.numericable.fr) (h 22 oke) [***] connected to the network (israel.il.us.*.com).
[Jul 07 22:12:19 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) left the network (israel.il.us.*.com).
[Jul 10 01:57:22 2008] LOGUSERS: *** (clochette@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (30 F) [***] connected to the network (israel.il.us.*.com).
[Jul 10 01:57:22 2008] LOGUSERS: *** (clochette@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (30 F) left the network (israel.il.us.*.com).
[Jul 12 02:10:29 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) [***] connected to the network (kings.il.us.*.com).
[Jul 12 02:10:30 2008] LOGUSERS: *** (mbullegg@***.rev.numericable.fr => *-DB577F91.rev.numericable.fr) (h 22 oke) left the network (kings.il.us.*.com).


/* Edit 2 */
OK...searched logs even more, there are a couple other addresses. When I'm done dealing with another issue I missed in my downtime a couple months ago, I'll go through again and find some more names, IP's and hosts...
Back to top
mouselike
Idler
Idler


Joined: 09 Dec 2003
Posts: 258

PostPosted: Jul 12, 2008 2:00am    Post subject: Reply with quote

theEd wrote:
greg27 wrote:
blocking these bots is easy, since they only seem to be connecting from a handful of hosts, but i'd really like to know what the point of these bots is. it's bizarre that they appear on so many networks yet nobody knows what they do :s


Yeah. What's the bet they're designed to confuse admins like us Razz


We use to get a lot of these on our network, they are spider bots. they fish from sites like g**glom for the possibility of filesharing bots on your network.

They maybe some other bots, but they look very familiar to what we had and just keep banning them is the only way around these.
Back to top
maddog906
Lurker
Lurker


Joined: 08 Mar 2005
Posts: 131
Location: uk

PostPosted: Jul 12, 2008 7:56am    Post subject: just makes you think Reply with quote

Is it one more move, from RIAA /media defender and all the other anti-file-sharing and anti p2p, what this world coming too? Gee you will find some one else hand wipe ya as (*) before you do and insert a tracking device
Back to top
phrozen77
Newbie
Newbie


Joined: 13 Jul 2004
Posts: 85
Location: There!! A 3-headed monkey, right behind you!

PostPosted: Jul 15, 2008 2:33am    Post subject: Reply with quote

[bang!]

Thats the few that we had yesterday evening, connecting, sitting there for a while and disconnecting again.

Wonder what theyre up to.

And no, the both hosts i've seen them connect from don't resolve to the same IP, infact they even seem to be 2 seperate ISPs.

[bang!] has address [bang!]
[bang!] has address [bang!]
Back to top
PingBad
Guru
Guru


Joined: 05 Feb 2005
Posts: 2064
Location: New Zealand

PostPosted: Jul 15, 2008 6:19am    Post subject: Reply with quote

zeke wrote:
So, shall we start a namelist?
Let's not.

I hate to be the hard-ass people, but word from the dude upstairs is that mentioning IP addresses and the like falls under naming names, sorry Sad
Back to top
dv8-123
none
none


Joined: 16 Jul 2008
Posts: 1
Location: Liverpool Uk

PostPosted: Jul 16, 2008 2:50pm    Post subject: Reply with quote

To be honest, Just look out for the rev.numericable.fr host mask ...
They never stick to the same channels, I have seen them in a number of them, I started doing a whois when i saw them join, now I just kill and make sure that some form of Gline is in place.
Back to top
Strawberry_Kittens
none
none


Joined: 28 Jun 2008
Posts: 5

PostPosted: Jul 26, 2008 4:00pm    Post subject: Reply with quote

Here are a couple of regexes that stop bots like that. Worked perfectly on my network.
Code:

^([a-zA-Z0-9]+)!([a-z0-9]+)@[^:]+:h \d\d
^([a-zA-Z0-9]+)!([a-z0-9]+)@[^:]+:\d\d F
Back to top
EcKstasy
Lurker
Lurker


Joined: 23 May 2008
Posts: 135
Location: Scotland

PostPosted: Jul 29, 2008 1:41pm    Post subject: CamBots Reply with quote

Yup,Those are called CamBots,They spam the network's users with PM's asking the users to go to sites where they can see the *real* people on cam (>>porn),Beware of those and often try to add a spamfilter for sandra_f as I've seen that one a few times,
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Help All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer