PDA

View Full Version : Last time I will ask: +S THE CHAN PLEASE



antares
09-25-2004, 01:23 PM
To those who don't know, "chan" = Hongfire's IRC channel.

(I've personally gone over this with Paizu many times before but the problem still remains.)

The problem: Spammer bots/botnet are spamming regular users besides the ops/hops. I'm not sure about voiced.

The old solution: There is a suggestion in the topic to set umode +X, which prevents PMs and notices from unregistered users.

The NEW problem: The attacker(s) have learned to make these bots register themselves with services. The spamming continues whether or not your are +X. Mode +X also has a negative side effect that notices from network services also get blocked. This is very cumbersome when you need to interact with them.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Why the problem remains unsolved:: The channel needs to remain "public", as I am told, in order to get more people to join. This may work for new channels. However, it has been proven from all this time that the channel has remained public that you are NOT getting any new users. The number of users have remained pretty constant for a long time now.

On the contrary, with users getting spammed over and over, more and more people will simply leave the channel. I for one have taken the chan off my auto-join list.

Believe me when I say that /list is now used mostly by spammers. Think about it. What are the chances that a normal user would perform a /list, sees the channel (besides all other public ones), and thinks to himself, "wow, I think I'm going to join this channel!". I'm convinced that the majority of those who come to the channel KNOW beforehand of the channel's existence without relying on /list.

The only plausible reason for making it public is so it would be seen when someone does a /whois on someone else. For this to work, you need as many people to be in the chan as possible to indirectly advertize for you. However, you may or may not realize that this is also another means for spammers to get to your chan. For the normal users who join the channel this way, they will be idling a while to see what's going on, be greeted with spams, get tired of them and leave. As these "advertizers" leave, it causes a snowball effect that makes this entire scheme fail.

The op/hops do not feel that this is a pressing issue because they're not the ones getting bothered by this.

The spamming occurs randomly at random time, but for those who are connected 24 hours a day, they will be sure to receive at least 3-4 of these a day. Not that many, but consider those who're connected 7 days a week and getting these everyday. The fact that there is an apparent solution that won't be implemented adds more to the frustration.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Making a chan +s is a safe practice. Only when you are losing significant number of people (e.g. down to half of what you have) or that spamming still persists regardless of +s, that you should consider other solutions. Making a channel public is NOT a solution.

eerodin
09-25-2004, 01:31 PM
The channel shouldn't be public, I don't understand why someone wants people who are completely uninvolved with HongFire in there anyway. I suck at joining new IRC channels... but sooner or later, I'm gonna drop by. ;)

HongFire
09-25-2004, 01:48 PM
Thanks for the feedback and suggestion. I didn't know about this until i read this post. I don't maintain MIRC my self since i am away from it most of the time. so i will get some other ops to work this out. Hopefully we will find a way to stop those spamers.

Paizu
09-25-2004, 04:12 PM
Turning to +S NOW since the spamer bots can register themselves and (!) they just stay in the channel for 1-2 sec (!).
I'm kicking many kind of bots for years but this kind of bots are just annoying bots. They have no ctcp reply which is totaly useless because they just stay in the channel for 1 sec. If I would detect them then they already away.
They have no regularity in the whois information so I can't ban them. The informations are filled with random letters.

antares
09-25-2004, 09:44 PM
Thanks Paizu ;)

Now, if spamming doesn't stop, we'll know for certain that they're indeed targeting specific channel(s). The ultimate solution is to create channel key and/or make it invite-only, but I understand we definitely don't want that as you will certainly lose users that way (not to mention the hassle it would generate). I just hope that the spamming ends there.

I think I witnessed once before an incident that targeted Hongfire's chan directly (since the bots were imitating Hong's alternate nick). Too bad I didn't keep the logs then. The "hey you" spam seem to be unrelated to that, though, so we'll see.

cuiviemen
09-25-2004, 10:16 PM
I guess you mean mode +s (secret) since rizon is not yet capable of handling connections made via ssl thus mode +S (channel for encrypted clients only) on channel have no function yet right? Or do you plan to enforce the channel mode +S when rizon will support it?

Egrimm
09-27-2004, 05:06 AM
I support the +s move, wondered for a long time why it weren't so as the benefits are larger than the problems as outlined above, but never got around to do anything.

Shragei
09-27-2004, 07:59 PM
The problem: Spammer bots/botnet are spamming regular users besides the ops/hops. I'm not sure about voiced.


Why not just setup a bot that bans by IP at the first sight of a url or ad and uses two users names. One of an OP, so it can ban. Another username that is ever changing to act as a spam detector

shivand1
09-27-2004, 09:10 PM
the problem is that spammers are getting to the point where they can fake IP addressess.

Edit: I've also been told that aol is a haven for spammers. This is because aol gives people who sign in a new IP each time they sign in. This has been a problem in aniverse so aniverse banned all users who use aol. Hope we don't have to resort to something that drastic.

Shragei
09-27-2004, 09:44 PM
well then the only other thing is to mute everyone and auto voice users after a period of time
oh, they are not spoofing there address its a network of zombie computer

Rasqual
09-28-2004, 04:44 PM
How is that going to help if all they do is grab the # users list and PM folks?

Shragei
09-29-2004, 05:01 AM
keeps them from spaming the channel but since they send spam directly to the person, then I'm stumped ^^;;

Paizu
09-29-2004, 08:52 AM
err...you guys really don't know about this kind of spamer bot
1) They don't spam in the channel. They join the channel and check the user list and part the channel (within 1 sec). THEN they pm 'Hey you!' one or more user of the channel.

in conclusion:
Spam dector => useless

They use random letters in their whois information.
For example:
Xqqkfaatw ~npyz@Rizon-3DAAF4F2.chvlva.adelphia.net * vquhqpz
Talatsq ~sxwm@Rizon-3CD56A6E.dsl.rcsntx.swbell.net * mrkonvz
Iitb ~ympyvq@360FFBDA.C7BD4DF4.4EC5F15E.IP * wyveqk

Do you see any regularity?

2) Since the channel is secret (+s). You can't see user whois information about our channel. If every channels, which you are on, are secret then it's like you are on no channels.

Shragei
09-29-2004, 09:09 AM
Its been awhile since I was on irc. The only bots I had to deal with were the channel spamer, so ya never had to deal with the ones you are talking about

Paizu
09-29-2004, 01:05 PM
Its been awhile since I was on irc. The only bots I had to deal with were the channel spamer, so ya never had to deal with the ones you are talking about

There also spamer you are talking about, but these bots what I'm talking is a new type of bots. What about to visite us?

#hf-network@irc.rizon.net

PlacidBlueAlien
10-03-2004, 09:06 AM
Most of the time, the bots join on a basis of channel size and hit the same rooms over and over since they are zombies. Not all of them should be +s. Unfortunately, you put the room on +s much too late as they already have the room down. :( With the amount of zombies the person doing this has, there isn't much you can do to stop it. The hostmasking Rizon enables probably doesn't make the job any easier either. IRCHighway had this problem awhile back with bots. While diligence in the room from the hops/ops/sops helped some; it really didn't amount to much besides a person being banned every few minutes. The bots only stopped when the IRCHighway network finally acted so you might want to ask some of the Rizon staff about what may be coming along. :)

Epicgamer
10-12-2004, 05:39 PM
You mean +s. +S is code stripping (bold, color, ect.) not secret.

Erm... Nevermind, someone already caught it. :P

moeru
10-13-2004, 03:08 AM
See..Now I'm gonna have to come idle like a fiend in there too =p I'm always on Rizon hanging out with one of the subbing groups

Para
10-13-2004, 08:24 AM
mmmm this is a done thread, chan is +s so locky locky!