The UnrealIRCd team does not officially provide support for any services packages that you may be using or want to use. This forum is provided so the community can help each other with services issues.
I was wondering if anyone running IrcDefender could help me with this. I posted it over on their forums but I've not had a reply yet and the forums look a little abandoned.
I'm using the version.pm module that came with ircdefender. I have the deny_version.conf in the root of my defender folder and I have the following lines in the deny_version.conf
subseven.+ G Subseven trojan drone.
Bottler.+ G XDCC Looker bots are not allowed here!
mIRC.+5\.+Bey W You are running an insecure mirc version, please upgrade.
mIRC.+3\.+ W Why are you running a 10 year old copy of mirc?
x-chat\s2\.0\.5 W Insecure x-chat version, please upgrade asap.
^35\sF$ G Stupid 35 F bots that part and join.
I'm trying to ban bots with the version reply of "35 F" without the quotes but it doesn't seem to be working. I'm no regexp expert but I'm sure my ban is right.
Can anyone help?
IrcDefender is defiantly checking the versions on connect.
By any chance they use nicknames like lidl22, lola22 ? (It's off-topic, I know, but those bots also connect to my server and I find it very annoying and I want to know who'se sending them..)
yeah, thats right it always seems to be girls names too. I'm sure there is an easy way to do it but i'd like to use IRCdefenders Version check for it. Earn its keep ::D
I don't think you need IRCDefender for that, as they connect from like two hostnames, so it would be a lot easier to just ban them manually. At least, that helps the best over here
Good luck and if you find out something more about it, please let me know !
Casper wrote:I don't think you need IRCDefender for that, as they connect from like two hostnames, so it would be a lot easier to just ban them manually. At least, that helps the best over here
Good luck and if you find out something more about it, please let me know !
I've found they connect from varying host names but from only 2 ISP's. wanadoo.fr and noos.fr From which their IP changes.
Hmm, thanks for the information. I don't have any French people connecting, so I just banned the whole ISP.
Do you know by the way wheter there is some organisation sending them or what they do? As far as I found out they just sit in a(n) (empty) empty channel and do like nothing...
Could it have something to do with the Israeli organisation which turned out to log the chats of several networks? I've heard they operated from several countries. I unfortuantely don't know from what countries..
Casper wrote:Could it have something to do with the Israeli organisation which turned out to log the chats of several networks? I've heard they operated from several countries. I unfortuantely don't know from what countries..
as an aside to this topic - if anyone still has these bots connecting from *@*.noos.fr ... pm one and it will reply and eventually ask if you have a webcam - 'they' seem to be from some web-cam service and are lightly spamming. The regex's listed by the previous poster work fine