we need help !!
Posted: Sun Jan 28, 2007 3:46 pm
hi
we have some problem with an BotNet since 4 days every day a BotNet with many Bots is connecting to our Irc Network, they are joinig same channels somtime so i have added the channels to the killchanlist in ircdefender, but it not realy kill all Bots only a few, we have glined all the ips but every day they will come back, there are no things the same not same nicks not same ident or so on, they didnt reply to finger or versions requests, our only help against them is defcon system from anope
we know that it is an other Network that attacks us we know the Network, its a turkish Network with around 1200 users, but what could we do against this network ?
here some examples
a whois of one of them
...
and so on i could post a Collection like a Book from these connects
any ideas to block this ?
p.s. sorry for my broken english i am german
we know that it is an other Network that attacks us we know the Network, its a turkish Network with around 1200 users, but what could we do against this network ?
here some examples
Code: Select all
14:27:09] <@ConnectServ> SIGNED ON user: KatiL ([email protected] - StRess) at: dream-irc.de
[14:27:17] <Global> OperServ: Talustus: defcon 1
[14:27:17] -OperServ- Services sind jetzt beim DEFCON 1
[14:27:17] -OperServ- * Keine neuen Channel-Registrierungen
[14:27:17] -OperServ- * Keine neuen Nicknamen-Registrierungen
[14:27:17] -OperServ- * keine MLOCK änderungen
[14:27:17] -OperServ- * Zwingt alle Channels die Modes (+miR) zu setzen
[14:27:17] -OperServ- * Benutzt das reduzierte Session-Limit von 1
[14:27:17] -OperServ- * Stilles ignorieren von non-opers
[14:27:17] -OperServ- * Setzt einen AKILL auf jeden NEU verbindenden Clienten
[14:27:17] <Global> Defcon level changed to 1 by Oper Talustus
[14:27:17] -Global- Das Defcon-Level ist jetzt auf Level: 1
[14:27:17] -Global- Security issues detected services in Defconmode
[14:27:17] <Global> DEFCON: setting +miR on all chan's
[14:27:17] * OperServ sets mode: +miR
[14:27:18] <Global> LOGUSERS: TnT ([email protected] => FC3709BC.8DF57D1E.7CCE9679.IP) (Monitor) [88.233.224.49] connected to the network (dream-irc.de).
[14:27:18] <@ConnectServ> SIGNED ON user: TnT ([email protected] - Monitor) at: dream-irc.de
[14:27:18] <Global> DEFCON: adding akill for *@88.233.224.49
[14:27:18] <Global> LOGUSERS: OcusTic ([email protected] => FC3709BC.8DF57D1E.7CCE9679.IP) (ProFiLe) [88.233.224.49] connected to the network (dream-irc.de).
[14:27:18] <@ConnectServ> SIGNED ON user: OcusTic ([email protected] - ProFiLe) at: dream-irc.de
[14:27:18] <Global> DEFCON: adding akill for *@88.233.224.49
[14:27:18] <Global> user: QUIT from nonexistent user OcusTic: User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:18] <Global> LOGUSERS: TnT ([email protected] => FC3709BC.8DF57D1E.7CCE9679.IP) (Monitor) left the network (dream-irc.de).
[14:27:18] <@ConnectServ> SIGNED OFF user: OcusTic ([email protected] - ProFiLe) at: dream-irc.de - User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:18] <@ConnectServ> SIGNED OFF user: TnT ([email protected] - Monitor) at: dream-irc.de - User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:19] <@ConnectServ> SIGNED ON user: KoRDoba ([email protected] - The_seYtanNN) at: dream-irc.de
[14:27:19] <Global> LOGUSERS: KoRDoba ([email protected] => 49FE7891.2A2D6CA5.7CCE9679.IP) (The_seYtanNN) [88.233.137.173] connected to the network (dream-irc.de).
[14:27:19] <Global> DEFCON: adding akill for *@88.233.137.173
[14:27:19] <Global> LOGUSERS: KoRDoba ([email protected] => 49FE7891.2A2D6CA5.7CCE9679.IP) (The_seYtanNN) left the network (dream-irc.de).
[14:27:19] <@ConnectServ> SIGNED OFF user: KoRDoba ([email protected] - The_seYtanNN) at: dream-irc.de - User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:20] <Global> LOGUSERS: inBoX ([email protected] => 6A2E93A6.3F3B928A.7EE77F11.IP) (Password) [86.123.46.102] connected to the network (dream-irc.de).
[14:27:20] <@ConnectServ> SIGNED ON user: inBoX ([email protected] - Password) at: dream-irc.de
[14:27:20] <Global> DEFCON: adding akill for *@86.123.46.102
[14:27:20] <@ConnectServ> SIGNED OFF user: inBoX ([email protected] - Password) at: dream-irc.de - OperServ (Session limit exceeded)
[14:27:20] <@ConnectServ> SIGNED OFF user: BeRDaNi ([email protected] - FaNatiK) at: dream-irc.de - User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:20] <Global> LOGUSERS: BeRDaNi ([email protected] => 6A2E93A6.3F3B928A.7EE77F11.IP) (FaNatiK) left the network (dream-irc.de).
[14:27:30] <@ConnectServ> SIGNED OFF user: iLetisim ([email protected] - Z-i-Y-a) at: dream-irc.de - User has been permanently banned from Dream-Irc (SpamBot by Talustus)
[14:27:30] <Global> LOGUSERS: iLetisim ([email protected] => FD1094A0.A8BD19EB.B0379ED3.IP) (Z-i-Y-a) left the network (dream-irc.de).
[14:27:33] <Global> LOGUSERS: Romeo ([email protected] => DreamUser-7BCDF65D.red-80-24-145.staticip.rima-tde.net) (ZeYNeL) [80.24.145.243] connected to the network (dream-irc.de).
[14:27:33] <@ConnectServ> SIGNED ON user: Romeo ([email protected] - ZeYNeL) at: dream-irc.de
[14:27:33] <Global> DEFCON: adding akill for *@243.Red-80-24-145.staticIP.rima-tde.net
[14:27:34] <@ConnectServ> SIGNED OFF user: Romeo ([email protected] - ZeYNeL) at: dream-irc.de - User has been banned from Dream-Irc (This network is currently not accepting connections, please try again later)
[14:27:34] <Global> LOGUSERS: Romeo ([email protected] => DreamUser-7BCDF65D.red-80-24-145.staticip.rima-tde.net) (ZeYNeL) left the network (dream-irc.de).Code: Select all
-=[ •••••••••••••••••••• -=[ Whois von Keko ]=-
-=[ Nickname: -=[ Keko ]
-=[ Realname: -=[ garibBoY ]
-=[ Hostmask: -=[ 8DB3CDB.E94CE238.60B65782.IP ]
-=[ Ident: -=[ BruceLee ]
-=[ Usermodes: -=[ +ixG ]
-=[ RealHost: -=[ *@88.226.39.10 ]
-=[ Channels: -=[ #dream-irc @#adana ]
-=[ Server: -=[ new-funpower.dream-irc.de ]
-=[ Connectet seit : -=[ Sunday 28/01/2007 14:23:32 ]
-=[ Ist still seit : -=[ 7secs ]
-=[ Online zeit : -=[ -72secs ]
-=[ •••••••••••••••••••• -=[ Whois von keko Ende > ]=and so on i could post a Collection like a Book from these connects
any ideas to block this ?
p.s. sorry for my broken english i am german