View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001174 | unreal | ircd | public | 2003-08-05 20:01 | 2003-11-20 19:43 |
| Reporter | Rocko | Assigned To | syzop | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Summary | 0001174: Ban Version aren't adding z:lines or g:lines | ||||
| Description | I heard, there is a new virus/trojan on the way (RPC-WORM), which are connecting over the RPC-Port 135 on windows platforms, and connect to IRC Networks, and from there, the owner can use the bots for DDoS. I have bots like them, and found a way, to ban them ALL (about 100 and more), because they use the same script. I used the Ban Version block, but the clients are reconnecting immediately after they quit. Isn't it possible, to add an option, or to let the server add Z:Lines for that clients, which get banned, because of the ban-version-block? I have 100 connects in 10 seconds and it will get more (I hope it will stop).. That makes many Traffic. I found a channel too, where the owner could give commands. There are bots posting something like -> Sub7Server v.Legends 2.1 installed on port: 7***, ip: 62.150.*** - victim: * - password: *--- The bots are joining a specified channel, I tried to ban everyone who was joining this channel, with the mirc on:join script. But that don´t work 100%, I don't know why, maybe some fault in mIRC or the IRCd, which don't recognize every join. I hope it could be fixed/added/changed, whatever, so that there is a good way to ban such clients/bots/ddosbots. I don't want to support channels, which have ddos bots. ;) | ||||
| 3rd party modules | |||||
|
|
quick&dirty patch: -- cd your-Unreal3.2-directory wget www.vulnscan.org/tmp/quick_banversion_zline.patch cat quick_banversion_zline.patch|patch -p0 make -- will add a 86400s (1 day) zline for every client banned by ban version, it's not configurable or something so this patch is not ment to be in the core unrealircd distribution.. it's just a quick help for your problem. |
|
|
The reason for this is, it's not supposed to. ban nick doesn't add a zline, ban realname doesn't add a zline, nothing adds a zline except a zline! |
|
|
I'm not too statisfied with the whole concept of z lines btw, because with zlines they keep connecting all the time (actually with g/k glines too :P) so you would have like a lot of connections/sec, another solution is to /shun but then they stay alive and are thus consuming file descriptors... so it's like file descriptors vs bandwith... Yes I know this is pretty off-topic.. anyway, in this case it would be like X numerics (001,002,etc) + motd and then a ban and an oper notice generated...vs... a zline (=no message sent by the ircd at all) reconnecting maybe twice as fast... what's best? lol ;) edited on: 08-06-03 04:32 |
|
|
Yes, I know it is not supposed to, I read the documentation. If you want to clear the network from something, like some DDoS-Bots, or XDCC-Bots, or other bots and and and...it would help when the server add z:lines, to prevent connections-floods or reconnect, because BOTS don't give up to reconnect. They don't know, that reconnect won't "help". That's the same with the fizzer modul.. it adds zlines too. It is only a third party modul, but it works fine, and prevent the fizzer bots to (re)connect. A quick patch too? Yes, and I'm (and maybe other people) still using it :) @syzop: Your patch works fine, thx, I will use that now for the above described reason. And to your question: The last one with the zline is better ;P And yes.. with z:lines they can reconnect to, but they get disconnected before they are connected (better than gline), so there isn´t so many traffic than a gline. Hm. Well, when no one other think, this could be a good Idea, to let ban version add zlines, you can close this bug report ;P. It was only a suggestion. I will use the patch then. |
|
|
IIRC people want(ed) zline (or gline) support because currently opers see a lots of notices (connect+disconnect) because they are banned after registration. |
|
|
Added in CVS .1965 - Added 'action' field to ban version { } which can be: kill: kills the user (default), tempshun: shun the specific connection only, kline/zline/gline/gzline/shun: place a ban on *@IP. Time of those bans can be specified in set::ban-version-tkl-time. It's up to the admin to take a good decision, sometimes zlines are best (=won't use much sockets but will reconnect quite quickly), sometimes tempshun (=will use 1 socket but generates nearly no network traffic), sometimes klines/glines, etc.. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-08-05 20:01 | Rocko | New Issue | |
| 2003-08-06 02:36 | syzop | Note Added: 0003413 | |
| 2003-08-06 02:54 |
|
Note Added: 0003414 | |
| 2003-08-06 04:32 | syzop | Note Added: 0003415 | |
| 2003-08-06 04:32 | syzop | Note Edited: 0003415 | |
| 2003-08-06 09:39 | Rocko | Note Added: 0003416 | |
| 2003-08-06 13:53 | syzop | Note Added: 0003417 | |
| 2003-10-31 13:48 | Rocko | Note Added: 0003900 | |
| 2003-10-31 13:51 | syzop | Status | new => resolved |
| 2003-10-31 13:51 | syzop | Resolution | open => fixed |
| 2003-10-31 13:51 | syzop | Assigned To | => syzop |
| 2003-11-20 19:43 | syzop | Status | resolved => closed |