CTCP Version Bans & Banning Bots
CTCP Version Bans & Banning Bots
My IRC network has reciently had a major attack of the bots, both XDCC Catcher, and Bottler. (IRC-Ork has been banned for some time and seems to not be a problem)
However the problems I am having is that the bots that I have banned via CTCP version replies are hammering the network attempting to connect. The servers all do have throttle settings, which DO work, but the bots seem to not be 'discouraged' by that. My SNotice window is handling so many connect attempts that it is impossible to scroll up and check out past connects. The window would just lock up because of incoming connects.
But my real problem is that I feel like all the bot connection attempts could make all 7 of my servers very hard to connect to, since they are all handling hundreds of blocked connect attempts per hour.
Is there any good way to prevent this from happening? (Thanks in advance.)
Darvocet ([email protected])
However the problems I am having is that the bots that I have banned via CTCP version replies are hammering the network attempting to connect. The servers all do have throttle settings, which DO work, but the bots seem to not be 'discouraged' by that. My SNotice window is handling so many connect attempts that it is impossible to scroll up and check out past connects. The window would just lock up because of incoming connects.
But my real problem is that I feel like all the bot connection attempts could make all 7 of my servers very hard to connect to, since they are all handling hundreds of blocked connect attempts per hour.
Is there any good way to prevent this from happening? (Thanks in advance.)
Darvocet ([email protected])
Hmm.. nope i havent tried changing connect ports, the problem i have with that is I believe most of the users on my network are... hmm how do you say... irc retards. So whre as many of them may understand the need to connect on 7000 or 6669 for a little while, I feel there will be hundreds that are too stupid to understand that.Solutech wrote:I think he means that he gets connect attempts . I can see where he's coming from . Even though he has gzlined the botnets they still try to connect . Have you considered swapping connects to a different port ? .
I have added:
Code: Select all
ban version {
mask "*XDCC Catcher*";
reason "XDCC Catcher bots are forbidden on this network.";
action gzline;
ban-time 24h;
};Darvocet
Luckily we havent had any botnets in our server . One of the main reasons Im happy to keep a small group of users is its easy to manage and you dont attract such attacks . For large networks I can imagine the headaches such things cause . The worst Ive had is a fool who thinks its fun to SYN flood me periodically . Hope you find a good solution to these botnets that works for you 
Ok guys, that gzline did prevent the connect attempts from showing in my SNotice window, which is super nice. It created a ton of glines though, which I guess is ok also. I just usually dont have any.Darvocet wrote:Well another problem i get with this (though it is tolerable) is now I have like 3,000 Glines.Although they will all timeout in 24h, so thats not too bad.
Thanks again for all the quick responses. Thats why I like unreal so much.
Darvocet.
I agree I enjoy running my small network. Because its small 100-300 users usually there are never server lags, rarely server splits, NEVER server attacks, and it makes for a much more comfortable network.Solutech wrote:Luckily we havent had any botnets in our server . One of the main reasons Im happy to keep a small group of users is its easy to manage and you dont attract such attacks . For large networks I can imagine the headaches such things cause . The worst Ive had is a fool who thinks its fun to SYN flood me periodically . Hope you find a good solution to these botnets that works for you
Darv.
-
WilliamWIkked
- Posts: 59
- Joined: Sun Jun 20, 2004 3:30 am
- Contact:
If you don't like all the glines, possibly just reduce the hours.. 24 hours is a long time if the bots keep getting new hosts.. you'll have too many glines in no time. I would try reducing it to like 10 hours or so, but that's just me.. If 24hrs works for you then by all means keep with it 
[insert another cliche sig here.]
Yea that isnt so bad of an idea. I am going to let it pile up for 24hours and see how many it turns out to be.WilliamWIkked wrote:If you don't like all the glines, possibly just reduce the hours.. 24 hours is a long time if the bots keep getting new hosts.. you'll have too many glines in no time. I would try reducing it to like 10 hours or so, but that's just me.. If 24hrs works for you then by all means keep with it