k-line

Help with EFnet related issues

Moderators: Website/Forum Admins, EFnet/Help Moderators

kraij
Posts: 3
Joined: Fri Jan 21, 2005 10:15 am

k-line

Postby kraij » Fri Jan 21, 2005 10:29 am

Hi everyone,

my problem is that my bot gets k-lined for ... let me say nothin...

well i get different info from servers why he gets banned. one time they detect an open proxy (absolutely nonsense!!!), the next server notices the host would be trojan infected. Maybe I am no geek but please tell me how a trojan or a simple virus could take use of a unixsystem (guess here I should say NONSENSE again). but thats not the story how it started.

The bot got a (connection closed) & when the eggdrop rejoined the channels he should protect, he became k-lined for spamming :x

Could it be that EFnet serversettings are a bit paranoid?

Sincerely kraij
User avatar
deww
Posts: 125
Joined: Fri Jul 18, 2003 7:17 pm

Re: k-line

Postby deww » Fri Jan 21, 2005 3:03 pm

Your bot might be on an "Unix" system, but it doesn't mean the IP address associated with the box was always clean. "Unix" based systems can be compromised and misconfigured as well. Some times they are configured to run services which are commonly exploitable or on ports which are commonly exploitable, hence the k-lines for trojans or opened proxies. Most of these klines are placed based on finding positive identification that the IP address you are using is either compromised or was compromised. They are not perfect, there are always legitimate users getting hit.. The "story" you mentioned seems innocent enough, but it did exhibit spam bot like behaviors and you seem to agree. Yes some of the automated bot detection routines can be sensitive, but it's necessary evil IMO.
User avatar
lucy
Posts: 234
Joined: Wed Jul 02, 2003 6:22 pm
Location: graceland
Contact:

Postby lucy » Fri Jan 21, 2005 6:48 pm

is it possible the bot sends an auto message to people joining the channel?

or is it possible it keeps cycling the channel trying to get opped?

either of those could cause klines
kraij
Posts: 3
Joined: Fri Jan 21, 2005 10:15 am

Postby kraij » Fri Jan 21, 2005 7:07 pm

nope, nothing u mentioned is the eggdrop doin

thx anyways
kraij
kraij
Posts: 3
Joined: Fri Jan 21, 2005 10:15 am

i could vomit ....

Postby kraij » Wed Feb 02, 2005 1:06 pm

ok I ve tried 4 different ip`s of the given range. 2 of them worked fine for a few hours. Now my eggdrop is banned again. the curiosity is that i have a second eggdrop on the same shell (workin fine), with an ip close to the ip of the banned eggdrop. Any idea folks?

I start takin it personally & since I ve read the post about abusing IRC-oper on EFnet I wouldnt wonder ....

ILLUMINATI ;)

regards kraij

Who is online

Users browsing this forum: No registered users and 35 guests