Home | Networks | Community | Need Help? 

 
 Quick search

 
 
 RegisterRegister   Log inLog in 

Proof of Previous post on Attacker BEWARE
Goto page 1, 2, 3  Next
 
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse
Author Message
mthwgrn
none
none


Joined: 09 Dec 2007
Posts: 28

PostPosted: Jan 27, 2008 10:53pm    Post subject: Proof of Previous post on Attacker BEWARE Reply with quote

My previous post was deleted because lack of proof. Simply save this image to your harddrive and zoom in if it is unreadable to you here. The user is searching the searchirc networks list and finding small networks where he can run rampid. I recommend a pm to myself if you want help in getting rid of this user before he even has the chance to join your network. I've seen him go by the nickname's qw and Purple}{aze on IRC and his searchirc Name is Dipset. I have his IP and hostname, I will not give it to anyone looking to attack him only for users looking to ban him from there network. His only intent is to flood bots nothing good.
Back to top
PingBad
Guru
Guru


Joined: 05 Feb 2005
Posts: 2012
Location: New Zealand

PostPosted: Jan 27, 2008 11:02pm    Post subject: Reply with quote

having personally seen these attacks myself - on this net, and others - i'll vouch for this
Back to top
Jobe
Idler
Idler


Joined: 30 Jul 2006
Posts: 349
Location: Lurking in the shadows of some random channel!

PostPosted: Jan 28, 2008 8:52am    Post subject: Reply with quote

Ive seen this attack too, all ove arounf 13 bots joined my net. Only 3 got past BOPM. Which made it easy to deal with.

The URL they spam changes though.

Code:
[02:24:44] -!- qw [logz@3eb9db92.208452fc.il.comcast.net] has joined #redial
[02:27:27] -!- QBzwqeWrVx [nwlvapnbdp@3d7b9bc1.268650f2.1c368726.IP] has joined #redial
[02:27:28] -!- uWeKdyi [ctbu@3d7b9bc1.268650f2.1c368726.IP] has joined #redial
[02:27:28] -!- BRUqWua [fdu@9e98fe9.3d7b9bc1.dsl.cavtel.net] has joined #redial
[02:27:31] < QBzwqeWrVx> http://81.22.91.102/~temp/money.exe
[02:27:31] < uWeKdyi> http://81.22.91.102/~temp/money.exe
[02:27:32] < uWeKdyi> http://81.22.91.102/~temp/money.exe
...
<snip>
...
[02:33:47] < qw> what is redial
[02:34:15] -!- qw [logz@3eb9db92.208452fc.il.comcast.net] has quit [Quit]


The last 2 lines were a few minutes after the 3 bots that survived were removed from the network.

One point I will mention though is if he's getting servers from SearchIRC he's going through deactivated listings too. Since my net (well not really mine) was delisted a while ago.
Back to top
Katlyn
none
none


Joined: 30 Sep 2006
Posts: 33

PostPosted: Jan 28, 2008 1:59pm    Post subject: Reply with quote

Hi,

He was also present on our network for a while (although either he didn't connect any bots, or wasn't able to) and made the channel #root# in which he claimed to be making 'fake' rxBots through mIRC scripting. He soon started to join channels with these supposed fake bots and spread links to downloads which never existed. (I doubt the link he was spamming there works).

Just looked at our services records and it seems that he still vists the network with the nickname qw.. however he has used both 'law' and 'gopzap' in the past.

His bots are just proxy bots and should be easily be stopped with any properly configured BOPM..

If it helps his email address is desiejp@hotmail.com (Sorry if we're not supposed to give out users details here).
Back to top
Mary
SearchIRC Admin
SearchIRC Admin


Joined: 03 May 2003
Posts: 692

PostPosted: Jan 28, 2008 2:09pm    Post subject: Reply with quote

We don't make a servers.ini and Jason has several programs in place to prevent mass harvesting of data from SearchIRC in order to prevent spambots and other botnets from using data published here to abuse networks.

Type the name of the connect server the bot used into Google and see how many websites come up. You'd be surprised how many channels tell users where to connect via their websites.
Back to top
mthwgrn
none
none


Joined: 09 Dec 2007
Posts: 28

PostPosted: Jan 28, 2008 5:07pm    Post subject: Mary Reply with quote

I am not blaming his attacks on SearchIRC. I love this site it's an excellent concept but anyone can view smaller networks from the Networks link on the site and go crash them. And usually more smaller networks seem to have inexperienced admins.

I just wanted to provide solid evidence as my previous post was deleted. I hope this one stays up for a while. Again, I will not post his information to the public but privately I will give his information so you can ban him from your network before he comes.

My community is small and friendly. I didn't have a bopm until 2 minutes after he left as I never needed it. It's just a shame that there are people out there that do such a thing.

Also, he is not a big threat. He connects through his real hostname and IP. His bots are weak and they do advertise a virus so beware of clicking on the link. I am glad demon-child (they have a relay bot to our network) found his bot source and figured out who it was. They didn't want to accept his link so he started flooding in bots. And then had the nerve to say "Guys I can help you get rid of them, it's easy" obviously cause they were his own bots. He went to purplesurge last night, also relayed to my network and tried the same but was banned.

Last night he used the nick Purple}{aze. Please BEWARE and mods please keep this post up and To the top (ttt)
Back to top
Mary
SearchIRC Admin
SearchIRC Admin


Joined: 03 May 2003
Posts: 692

PostPosted: Jan 28, 2008 5:58pm    Post subject: Reply with quote

No worries. Some people do think that listing their network will bring attacks. Obviously if you can see a network on SearchIRC (or any other site, for that matter) so can other people - including those who try to do you harm. Not much anyone can do about that except have a completely private, unadvertised IRC network. Like I said, for most networks, Googling your servers will get dozens if not hundreds of results.

The attack you documented was fortunately very mild, and can actually serve as a good learning experience for you and your staff. Keep your opers sendq limits up high so they don't get flooded off, script your channel bots to mode your channel +im when there's a large influx of users, use BOPM and any feature your service pack has to mitigate bot attacks, and then experience will teach you to laugh at the rest.
Back to top
dacayhero
Lurker
Lurker


Joined: 26 Jan 2008
Posts: 191

PostPosted: Jan 28, 2008 10:25pm    Post subject: Reply with quote

hmmm qw keeps coming on my server asking to link to me though hes never flooded blitzx.net yet ill keep my eye on her
Back to top
SasukeUchiha
Lurker
Lurker


Joined: 01 Dec 2007
Posts: 114
Location: California

PostPosted: Jan 28, 2008 11:18pm    Post subject: Reply with quote

:O iv seen that before on my friends serv
Back to top
mthwgrn
none
none


Joined: 09 Dec 2007
Posts: 28

PostPosted: Jan 29, 2008 5:54pm    Post subject: dacayhero Reply with quote

You are very lucky to not have the bots loaded. It may be because you have a proxy monitor. If you do he can't do it. He's small time. Next time he connects get his ip so you can quickly akill/szline him/her when it starts. Because it will.
Back to top
dacayhero
Lurker
Lurker


Joined: 26 Jan 2008
Posts: 191

PostPosted: Jan 29, 2008 10:50pm    Post subject: Reply with quote

he was asking about my ciscos so who knows
Back to top
greg27
Lurker
Lurker


Joined: 07 Oct 2006
Posts: 136
Location: Australia

PostPosted: Jan 31, 2008 4:33am    Post subject: Reply with quote

if you use unrealircd, a good +f will save your channel from pathetic attack attempts like these. a bopm using ahbl, efnet bl, etc. (and the cbl if you're really paranoid, but personally that gets too many false positives for me to justify using) will also filter out a fair bit of the crap. irc defender also has a module which is good against these types of floods.
Back to top
Anarchy
Lurker
Lurker


Joined: 26 Oct 2007
Posts: 137
Location: Cabot Arkansas

PostPosted: Jan 31, 2008 9:22pm    Post subject: Reply with quote

ive seen this attack. these people have no life.
Back to top
SasukeUchiha
Lurker
Lurker


Joined: 01 Dec 2007
Posts: 114
Location: California

PostPosted: Feb 01, 2008 8:11am    Post subject: Reply with quote

Alot of proxy users have been around Lucidchat lately
Back to top
dipset
none
none


Joined: 26 Jan 2008
Posts: 14

PostPosted: Feb 01, 2008 3:22pm    Post subject: fakkeee Reply with quote

fake, thats not qw
Back to top
Display posts from previous:   
Post new topic   Reply to topic    SearchIRC Forum Index -> IRC Abuse All times are GMT - 6 Hours
Goto page 1, 2, 3  Next
Page 1 of 3

 
 
Forum powered by phpBB
 
 © 2000 - 2008 EverythingIRC, Inc. All rights reserved. Please read our disclaimer