Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

clone attacks
Goto page Previous  1, 2, 3  Next
 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse
Author Message
hitnrun
none
none


Joined: 28 Jul 2006
Posts: 2

PostPosted: Jul 28, 2006 8:38pm    Post subject: Reply with quote

Yes. some1 with the name Scottt / Scott -Rule / Scottz -Rule / ScotT / ScoTt, and other simialr names has been attacking our network with ClonesX v1.501b by kRaiX.
This person is a real script kiddie and we dont know a good way to handle this. If anyone else has had problems with him plz let me know and how you handled it.

He is rlly getting on our nerves. has about 100 clones join our chat channel and spam it rlly baddly.
Back to top
FBI
Guru
Guru


Joined: 19 Aug 2005
Posts: 1494
Location: Federation Of Bored IRC'ers

PostPosted: Jul 28, 2006 8:41pm    Post subject: Reply with quote

hitnrun wrote:
Yes. some1 with the name Scottt / Scott -Rule / Scottz -Rule / ScotT / ScoTt, and other simialr names has been attacking our network with ClonesX v1.501b by kRaiX.
This person is a real script kiddie and we dont know a good way to handle this. If anyone else has had problems with him plz let me know and how you handled it.

He is rlly getting on our nerves. has about 100 clones join our chat channel and spam it rlly baddly.


Use BOPM and limit your clone per ip...
and hmmmm use Anope Defcon 1 if need be and enable if u didn't

btw read your pm


Last edited by FBI on Jul 28, 2006 8:45pm; edited 2 times in total
Back to top
hitnrun
none
none


Joined: 28 Jul 2006
Posts: 2

PostPosted: Jul 28, 2006 8:44pm    Post subject: Reply with quote

ok cool. Awesome.. How?
Back to top
FBI
Guru
Guru


Joined: 19 Aug 2005
Posts: 1494
Location: Federation Of Bored IRC'ers

PostPosted: Jul 28, 2006 8:49pm    Post subject: Reply with quote

hitnrun wrote:
ok cool. Awesome.. How?


if u don't wanna use BOPM and u could use opsb and blsb and config it....
unreal spamfilters works too



if u still need help pm me heh.... Razz Razz
Back to top
slcker76
none
none


Joined: 22 Feb 2004
Posts: 3

PostPosted: Jul 28, 2006 8:54pm    Post subject: Reply with quote

this idiot has been dealt with, the point of the post should be to warn people about this clown, i was trying to be nice and help him set up anope, if he comes asking for help tell him to fuk himself
Back to top
SATAN-HHH
Eleet
Eleet


Joined: 29 Nov 2003
Posts: 855
Location: Texas

PostPosted: Jul 30, 2006 6:26pm    Post subject: Reply with quote

FBI wrote:
hitnrun wrote:
ok cool. Awesome.. How?


if u don't wanna use BOPM and u could use opsb and blsb and config it....
unreal spamfilters works too



if u still need help pm me heh.... Razz Razz



I'd think if they use about the same nicks, the last suggestion'd be best. Restrict that and variations of the real name in unreal conf.
Back to top
Tranqerr
none
none


Joined: 24 Mar 2005
Posts: 11

PostPosted: Aug 05, 2006 7:16am    Post subject: Reply with quote

If using unreal (which is possible as many do with anope) this should work;

/spamfilter add u gline 3h Botnet [0-9][a-z]{5}![0-9][a-z]{5}@.+
Back to top
FBI
Guru
Guru


Joined: 19 Aug 2005
Posts: 1494
Location: Federation Of Bored IRC'ers

PostPosted: Aug 05, 2006 12:30pm    Post subject: Reply with quote

Tranqerr wrote:
If using unreal (which is possible as many do with anope) this should work;

/spamfilter add u gline 3h Botnet [0-9][a-z]{5}![0-9][a-z]{5}@.+



SQline helps too if the clone are using somethign like *clone2* and clone clone clone...etc etc etc...
Back to top
Jappy
none
none


Joined: 28 Jun 2004
Posts: 9

PostPosted: Aug 05, 2006 3:19pm    Post subject: Reply with quote

for noestats secureserv , that line gline for a few hour all user from a1234 to abcd1234 , that all clonex

Clonex4 2 0 0 "(?i)^[[:alpha:]]{1,4}[[:digit:]]{4}$" "Youre nick is known as as Clonex drones please change nick !" 1
Back to top
bzed
none
none


Joined: 01 Dec 2006
Posts: 6

PostPosted: Dec 01, 2006 9:03pm    Post subject: Reply with quote

Looks like a good solution to me. Should try it out.
Back to top
Niphyr
none
none


Joined: 13 Jun 2006
Posts: 1

PostPosted: Jan 15, 2007 12:44am    Post subject: Reply with quote

Here is a spamfilter that will trap them evertime:

Code:
/spamfilter add u gzline 30d Potential_malicious_client._Quarantine_in_effect.^[a-z][0-9]{3,4}!


That will stop those variations of the pathetic clones script from working. Other ideas would be place bans for lemming*!lemming@* and smurf*!smurf@* as they are the other 2 default variatons for the script.

Just be thankful the version in question wasn't one of the variations i've seen that utilises completely random aleatory nicknames/idents/real names.

If they continue to flood you using the clonesxs script and you want some further assistance feel free to contact me. I'm finding that to be more and more commonly used. Beats an actual botnet I suppose...
Back to top
Inudbz
none
none


Joined: 02 Dec 2004
Posts: 33

PostPosted: Jan 25, 2007 4:24pm    Post subject: Reply with quote

Law, Do it like the pro's do it, BPM and Defcon is really helpful but !@#$ that, Set up a force join script like #lobby and then setup a popup for gline and get every one of those cock suckers at once.

Yeah^, Bleh, I've have been around for 10+ years and have used those proxy mass bot scripts, Use what the punks are using and learn how to get rid of them. Look up on google too if you want, and search for socks 5 proxies, see which ports there are and add it to the scanner in bopm, Helps get rid of alot of them and having more then one dnsbl works too.
Back to top
AviZ
none
none


Joined: 20 Jan 2007
Posts: 10

PostPosted: Jan 26, 2007 12:59pm    Post subject: Reply with quote

theres more than one way to skin a cat
Back to top
SATAN-HHH
Eleet
Eleet


Joined: 29 Nov 2003
Posts: 855
Location: Texas

PostPosted: Jan 27, 2007 8:25pm    Post subject: Reply with quote

Atheme users also have the option to add the nickname variation to rawatch and set the akill/zline option on. Yes, I do realize that you could *possibly* risk killing other users with it, so I'd be careful. There are definently alot of options out there though, if you do your research on the ircd and services you run and get to know them properly.
Back to top
Katlyn
Newbie
Newbie


Joined: 30 Sep 2006
Posts: 50

PostPosted: Mar 22, 2007 1:33pm    Post subject: Reply with quote

Hi,

A good way to remove the clones effectively and without affecting other users is to implement some sort of 'Trace' command into your services.

srvx already has this implemented and there is a copy of it for Anope (although you'll need to make some modifications for it to work properly) here.. http://www.anope.org/modules/os_trace.c

On our network (where we get alot of clone attacks) we have the trace command modified to include ? for letters and % for numbers, so if for example we had the bots that you had connecting then we could issue a command similar to /os trace akill nick ?%%%% ident ~?%%%%

There are tons of different trace criterias (eg. numchannels, nickage, channels, ident, vhost, mask, identify yes/no) which makes it very easier to track down clones, especially on a smaller network.

It's definately worth having BOPM as not only will it remove some of the clones but it will also alert you to any that are connecting.. A good blacklist at the moment is the EFnet rbl - http://rbl.efnet.org - unlike alot of the blacklists the entries are cleaned out regularly so you won't have false-positives turning up all the time.

-Katlyn
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse All times are GMT - 6 Hours
Goto page Previous  1, 2, 3  Next
Page 2 of 3

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer