Bot IP Scan Help

"irc.teklan.com.tr - #Help" <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
Hi, I am new to this mailing list.

we have been using bopm on our sever for a long time. since we last updated 
with the last version, we have been having flood attacks on the server. i 
wanted to get more information from you by giving you the IP adrdess and the 
ports because these bots connect to the server with around 50 and 100 
connections. 

these are examples of the bots nicks and idents
* f2r1p37l1j43 ([email protected]) has joined #Zurna
* q8N2PDFJI638 ([email protected]) has joined #Zurna
* vh38bmh8v ([email protected]) has left #Zurna
* nk62jtls ([email protected]) has left #Zurna
* wRH4534XW627X9379DA ([email protected]) has joined #Zurna
* a93OAU9BH35TR ([email protected]) has joined #Zurna

and these are the messages that the bots flood the channel with
[02:36:49] <p222P5J6M5EG>  
flo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dfl
o0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0
dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dflo0dfl

And these are the actual IPs.
82.140.204.163
adsl-211-208-167.mia.bellsouth.net
dyn-81-166-241-72.ppp.tiscali.fr
a213-22-252-186.netcabo.pt
81.84.5.48

these are the open ports of the bots during the time of the attacks.
 82.140.204.163
 Port       State       Service
 135/tcp    open        loc-srv                 
 139/tcp    open        netbios-ssn             
 389/tcp    open        ldap                    
 445/tcp    open        microsoft-ds            
 1002/tcp   open        unknown                 
 1025/tcp   open        listen                  
 5000/tcp   open        fics

 chtn1-1459.pei.aliant.net
 Port       State       Service
 21/tcp     open        ftp                     
 25/tcp     filtered    smtp                    
 135/tcp    filtered    loc-srv                 
 139/tcp    filtered    netbios-ssn             
 389/tcp    open        ldap                    
 445/tcp    filtered    microsoft-ds            
 1002/tcp   open        unknown                 
 1025/tcp   open        listen                  
 4444/tcp   filtered    krb524                  
 5000/tcp   open        fics                    

I'm giving you the IPs from these flood attacks, and if you could tell me 
whether they are proxy or not. Or if you could tell me how I can get the bot 
to tell me if it is a proxy, I would really appreciate it.

a213-22-106-160.netcabo.pt
cm-net-poa-C8B0C2A7.brdterra.com.br
courbevoie-105-1-13.net1.nerim.net
chtn1-1459.pei.aliant.net
ACC5EC50.ipt.aol.com

When we do a check with the bot, this is the response it gives.
[02:48:29] <^^zZz^^> SecureProxy check ACC5EC50.ipt.aol.com
[02:48:29] <SecureProxy> CHECK -> Checking '172.197.236.80' for open proxies 
on all scanners
[02:48:30] <SecureProxy> CHECK -> DNSBL -> 172.197.236.80 does not appear in 
BL zone opm.blitzed.org
[02:48:30] <SecureProxy> CHECK -> All tests on 172.197.236.80 completed.


We could really use some help. 
Thank you

--


Teklan Internet Erisim Hizmetleri
	    http://www.teklan.net
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.