mIRC Home    About    Download    Register    News    Help

Print Thread
#97201 09/09/04 11:11 PM
Joined: Dec 2003
Posts: 2
E
Elm Offline OP
Bowl of petunias
OP Offline
Bowl of petunias
E
Joined: Dec 2003
Posts: 2
Hey, dunno if this is the right place to post this but maybe someone could help?

I help run a network and for the past 3-4 days have constantly been bot flooded by a botnet it would seem..
Normally we have been able to use our bopm bots to block and catch them but in this instance it seems near impossible and its rapidly filling up the autokill lists. The services are all offered for free so this is not something we would like to continue.
Used to be able to catch the bots by using the freelists that are most commonly banned and blocking the ports used but now the bots/hosts/ips used dont seem to exist and seem to mainly be *.wannado.fr and *.do hosts and a lot of *.ca thrown in also..

Anyone have any ideas of how to help catch the hosts or lookup the hosts so we can put a stop to this?

Thanks in advance for any help offered.

#97202 10/09/04 01:11 AM
Joined: Feb 2003
Posts: 372
R
Fjord artisan
Offline
Fjord artisan
R
Joined: Feb 2003
Posts: 372
Hm, this sounds like a ddos, in which case the attacks are coming from a lot of random IPs around the globe. There's not much you can do, except change your IP often, which will also require you to update your DNS often.

#97203 11/09/04 07:44 PM
Joined: Aug 2003
Posts: 309
N
Fjord artisan
Offline
Fjord artisan
N
Joined: Aug 2003
Posts: 309
do you remember angering anyone recently? possibly close all your ports and open an unusual port for irc? or you can just wait it out.


-Nick (Darko)
-Admin irc.aussiechat.org
-#Chatzone, #helpdesk
#97204 12/09/04 01:14 AM
Joined: Dec 2002
Posts: 2,962
S
Hoopy frood
Offline
Hoopy frood
S
Joined: Dec 2002
Posts: 2,962
Quote:
There's not much you can do, except change your IP often, which will also require you to update your DNS often.

- There's no point changing your IP and then updating your DNS since that will nullify the effect of changing your IP in the first place (unless the people who initiated the DDoS were incredibly stupid and targeted the IP address instead of the hostname).


Spelling mistakes, grammatical errors, and stupid comments are intentional.
#97205 12/09/04 12:08 PM
Joined: Dec 2002
Posts: 2,985
Hoopy frood
Offline
Hoopy frood
Joined: Dec 2002
Posts: 2,985
k:lines on a bot that can repeatedly attack is useless, use z:line instead (on the IP) as this stops the bot even knowing your server exists. A k:line allows a client to connect before being dealt with whereas a z:line is a firewall and disallows the connection initially. I think z:line is also called a d:line on some servers. Better still, if your IRCd offers a seperate command to store z/d:lines permanently then use that and there's a good chance that particular botnet won't be able to reoffend. Once again the list of bans may be big but this is better than being nailed.

People who run botnets to flood with have what is called small penis syndrome, amazing what turns them on ay. One last thing, there is nothing that can be done to stop the attacks but at least with the IP bans you can save your server from reacting to what is thrown at it.

#97206 22/09/04 09:17 PM
Joined: Aug 2003
Posts: 309
N
Fjord artisan
Offline
Fjord artisan
N
Joined: Aug 2003
Posts: 309
thats a whole lots of ips to ban. on aussiechat we had a botnet of almost 200 all with different hosts. and even then they kept coming back frown


-Nick (Darko)
-Admin irc.aussiechat.org
-#Chatzone, #helpdesk
#97207 23/09/04 09:58 AM
Joined: Dec 2002
Posts: 2,985
Hoopy frood
Offline
Hoopy frood
Joined: Dec 2002
Posts: 2,985
Quite correct, but it is a case of choosing the better of two evils. A long untidy ban list is better than not existing.


Link Copied to Clipboard