|
|
| Author |
Message |
hitnrun none

Joined: 28 Jul 2006 Posts: 2
|
Posted: Jul 28, 2006 8:38pm Post subject: |
|
|
Yes. some1 with the name Scottt / Scott -Rule / Scottz -Rule / ScotT / ScoTt, and other simialr names has been attacking our network with ClonesX v1.501b by kRaiX.
This person is a real script kiddie and we dont know a good way to handle this. If anyone else has had problems with him plz let me know and how you handled it.
He is rlly getting on our nerves. has about 100 clones join our chat channel and spam it rlly baddly. |
|
| Back to top |
|
 |
FBI Guru

Joined: 19 Aug 2005 Posts: 1494 Location: Federation Of Bored IRC'ers
|
Posted: Jul 28, 2006 8:41pm Post subject: |
|
|
| hitnrun wrote: | Yes. some1 with the name Scottt / Scott -Rule / Scottz -Rule / ScotT / ScoTt, and other simialr names has been attacking our network with ClonesX v1.501b by kRaiX.
This person is a real script kiddie and we dont know a good way to handle this. If anyone else has had problems with him plz let me know and how you handled it.
He is rlly getting on our nerves. has about 100 clones join our chat channel and spam it rlly baddly. |
Use BOPM and limit your clone per ip...
and hmmmm use Anope Defcon 1 if need be and enable if u didn't
btw read your pm
Last edited by FBI on Jul 28, 2006 8:45pm; edited 2 times in total |
|
| Back to top |
|
 |
hitnrun none

Joined: 28 Jul 2006 Posts: 2
|
Posted: Jul 28, 2006 8:44pm Post subject: |
|
|
| ok cool. Awesome.. How? |
|
| Back to top |
|
 |
FBI Guru

Joined: 19 Aug 2005 Posts: 1494 Location: Federation Of Bored IRC'ers
|
Posted: Jul 28, 2006 8:49pm Post subject: |
|
|
| hitnrun wrote: | | ok cool. Awesome.. How? |
if u don't wanna use BOPM and u could use opsb and blsb and config it....
unreal spamfilters works too
if u still need help pm me heh....  |
|
| Back to top |
|
 |
slcker76 none

Joined: 22 Feb 2004 Posts: 3
|
Posted: Jul 28, 2006 8:54pm Post subject: |
|
|
| this idiot has been dealt with, the point of the post should be to warn people about this clown, i was trying to be nice and help him set up anope, if he comes asking for help tell him to fuk himself |
|
| Back to top |
|
 |
SATAN-HHH Eleet

Joined: 29 Nov 2003 Posts: 855 Location: Texas
|
Posted: Jul 30, 2006 6:26pm Post subject: |
|
|
| FBI wrote: | | hitnrun wrote: | | ok cool. Awesome.. How? |
if u don't wanna use BOPM and u could use opsb and blsb and config it....
unreal spamfilters works too
if u still need help pm me heh....  |
I'd think if they use about the same nicks, the last suggestion'd be best. Restrict that and variations of the real name in unreal conf. |
|
| Back to top |
|
 |
Tranqerr none

Joined: 24 Mar 2005 Posts: 11
|
Posted: Aug 05, 2006 7:16am Post subject: |
|
|
If using unreal (which is possible as many do with anope) this should work;
/spamfilter add u gline 3h Botnet [0-9][a-z]{5}![0-9][a-z]{5}@.+ |
|
| Back to top |
|
 |
FBI Guru

Joined: 19 Aug 2005 Posts: 1494 Location: Federation Of Bored IRC'ers
|
Posted: Aug 05, 2006 12:30pm Post subject: |
|
|
| Tranqerr wrote: | If using unreal (which is possible as many do with anope) this should work;
/spamfilter add u gline 3h Botnet [0-9][a-z]{5}![0-9][a-z]{5}@.+ |
SQline helps too if the clone are using somethign like *clone2* and clone clone clone...etc etc etc... |
|
| Back to top |
|
 |
Jappy none

Joined: 28 Jun 2004 Posts: 9
|
Posted: Aug 05, 2006 3:19pm Post subject: |
|
|
for noestats secureserv , that line gline for a few hour all user from a1234 to abcd1234 , that all clonex
Clonex4 2 0 0 "(?i)^[[:alpha:]]{1,4}[[:digit:]]{4}$" "Youre nick is known as as Clonex drones please change nick !" 1 |
|
| Back to top |
|
 |
bzed none

Joined: 01 Dec 2006 Posts: 6
|
Posted: Dec 01, 2006 9:03pm Post subject: |
|
|
| Looks like a good solution to me. Should try it out. |
|
| Back to top |
|
 |
Niphyr none

Joined: 13 Jun 2006 Posts: 1
|
Posted: Jan 15, 2007 12:44am Post subject: |
|
|
Here is a spamfilter that will trap them evertime:
| Code: | | /spamfilter add u gzline 30d Potential_malicious_client._Quarantine_in_effect.^[a-z][0-9]{3,4}! |
That will stop those variations of the pathetic clones script from working. Other ideas would be place bans for lemming*!lemming@* and smurf*!smurf@* as they are the other 2 default variatons for the script.
Just be thankful the version in question wasn't one of the variations i've seen that utilises completely random aleatory nicknames/idents/real names.
If they continue to flood you using the clonesxs script and you want some further assistance feel free to contact me. I'm finding that to be more and more commonly used. Beats an actual botnet I suppose... |
|
| Back to top |
|
 |
Inudbz none

Joined: 02 Dec 2004 Posts: 33
|
Posted: Jan 25, 2007 4:24pm Post subject: |
|
|
Law, Do it like the pro's do it, BPM and Defcon is really helpful but !@#$ that, Set up a force join script like #lobby and then setup a popup for gline and get every one of those cock suckers at once.
Yeah^, Bleh, I've have been around for 10+ years and have used those proxy mass bot scripts, Use what the punks are using and learn how to get rid of them. Look up on google too if you want, and search for socks 5 proxies, see which ports there are and add it to the scanner in bopm, Helps get rid of alot of them and having more then one dnsbl works too. |
|
| Back to top |
|
 |
AviZ none

Joined: 20 Jan 2007 Posts: 10
|
Posted: Jan 26, 2007 12:59pm Post subject: |
|
|
| theres more than one way to skin a cat |
|
| Back to top |
|
 |
SATAN-HHH Eleet

Joined: 29 Nov 2003 Posts: 855 Location: Texas
|
Posted: Jan 27, 2007 8:25pm Post subject: |
|
|
| Atheme users also have the option to add the nickname variation to rawatch and set the akill/zline option on. Yes, I do realize that you could *possibly* risk killing other users with it, so I'd be careful. There are definently alot of options out there though, if you do your research on the ircd and services you run and get to know them properly. |
|
| Back to top |
|
 |
Katlyn Newbie

Joined: 30 Sep 2006 Posts: 50
|
Posted: Mar 22, 2007 1:33pm Post subject: |
|
|
Hi,
A good way to remove the clones effectively and without affecting other users is to implement some sort of 'Trace' command into your services.
srvx already has this implemented and there is a copy of it for Anope (although you'll need to make some modifications for it to work properly) here.. http://www.anope.org/modules/os_trace.c
On our network (where we get alot of clone attacks) we have the trace command modified to include ? for letters and % for numbers, so if for example we had the bots that you had connecting then we could issue a command similar to /os trace akill nick ?%%%% ident ~?%%%%
There are tons of different trace criterias (eg. numchannels, nickage, channels, ident, vhost, mask, identify yes/no) which makes it very easier to track down clones, especially on a smaller network.
It's definately worth having BOPM as not only will it remove some of the clones but it will also alert you to any that are connecting.. A good blacklist at the moment is the EFnet rbl - http://rbl.efnet.org - unlike alot of the blacklists the entries are cleaned out regularly so you won't have false-positives turning up all the time.
-Katlyn |
|
| Back to top |
|
 |
|