<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/13200" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2007-04-30T04:24:30-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/13200</id>

		<entry>
		<author><name><![CDATA[silverboy]]></name></author>
		<updated>2007-04-30T04:24:30-04:00</updated>

		<published>2007-04-30T04:24:30-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=72375#p72375</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=72375#p72375"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=72375#p72375"><![CDATA[
the script banned out my bnc's... i dont think they had the above mentioned ports open so i removed the tcl from my eggdrop :/<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7362">silverboy</a> — Mon Apr 30, 2007 4:24 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-10T01:29:41-04:00</updated>

		<published>2007-03-10T01:29:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71137#p71137</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71137#p71137"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71137#p71137"><![CDATA[
If the variable banport is in the proxycheck script, yes you can add more to it, I dont have the script any longer to look at it, and for your 2nd question, yes you can comment out the putserv line or delete if you prefer to stop sending kick notices to the users.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Sat Mar 10, 2007 1:29 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[silverboy]]></name></author>
		<updated>2007-03-09T23:01:11-04:00</updated>

		<published>2007-03-09T23:01:11-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71134#p71134</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71134#p71134"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71134#p71134"><![CDATA[
<div class="codebox"><p>Code: </p><pre><code>  variable banport "1080,1081,3380,3381" ;# Most commen port list</code></pre></div>it does kick. socks 4 common port = 1080 <br>or does it only kick this port list? if so can i add some more ports to it... <br><br><br>between the tcl sends warning to the users via NOTICE, how to disable this?<br><br>shud i remove these lines?<br><div class="codebox"><p>Code: </p><pre><code>   putserv "NOTICE $nick :$warnmsg"</code></pre></div><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7362">silverboy</a> — Fri Mar 09, 2007 11:01 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-08T15:09:55-04:00</updated>

		<published>2007-03-08T15:09:55-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71096#p71096</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71096#p71096"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71096#p71096"><![CDATA[
If there is a sock4 dnsbl, sure.. Try google searching for "socks4 dnsbl"  and the link for proxyscan was posted in this thread, or just search the tcl archive for proxyscan, it's in the archive.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Thu Mar 08, 2007 3:09 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[silverboy]]></name></author>
		<updated>2007-03-08T02:13:06-04:00</updated>

		<published>2007-03-08T02:13:06-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71084#p71084</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71084#p71084"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71084#p71084"><![CDATA[
does the Proxyscan.tcl detec Socks4 as well?<br><br>where can i get to download this one.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7362">silverboy</a> — Thu Mar 08, 2007 2:13 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-07T02:26:42-04:00</updated>

		<published>2007-03-07T02:26:42-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71060#p71060</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71060#p71060"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71060#p71060"><![CDATA[
<blockquote class="uncited"><div>if ur doin it the other way eggdrop is damn slower.!</div></blockquote>proxyscan.tcl looked pretty fast to me.. Anyone care to use [time] on it and find out exactly how many milliseconds it takes to get the info from a half dozen dnsbl's with it? If I had to guess, I'd say it took maybe 1/100th of a sec to look up the test IP I tried in the 5 dnsbl's..<br><br>Of course, there's always the possibility that one of the dnsbl servers doesn't respond immediately, and I already deleted the proxyscan script, so I dont know offhand if/how it handles timeouts. <br><br>Considering that it does the query in 1 one proc and handles the response in a separate proc, I don't see any reason it would lag the bot.  I suppose the join bind might lag the bot if the channel is extremely busy, but dnsbl lookups as done in proxyscan.tcl is a damn sight faster than the method I had in mind =)<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Wed Mar 07, 2007 2:26 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[silverboy]]></name></author>
		<updated>2007-03-07T01:56:22-04:00</updated>

		<published>2007-03-07T01:56:22-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71056#p71056</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71056#p71056"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71056#p71056"><![CDATA[
ban ?1*!~*@* ?2*!~*@*  ?3*!~*@*  ?4*!~*@*  ?4*!~*@*  ?5*!~*@* ?6*!~*@* ?7*!~*@* ?8*!~*@* ?9*!~*@* and no nicks like that will join your channel.<br><br><br>if ur doin it the other way eggdrop is damn slower.!<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7362">silverboy</a> — Wed Mar 07, 2007 1:56 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-07T01:55:35-04:00</updated>

		<published>2007-03-07T01:55:35-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71055#p71055</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71055#p71055"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71055#p71055"><![CDATA[
<blockquote class="uncited"><div>Although converting these into something usable should'nt be that hard, it surely indicates the service-provider don't want ppl mining it, and is prepared to do quite alot to prevent ppl from doing it...<br>Besides, dnsbl is pretty standardized these days.</div></blockquote>In their defense, they do provide an .htaccess formatted file, but, why bother making a new script when dnsbl+proxyscan will do the job infinitely faster than any other method I could think of?  I was thinking of pulling the data from the htaccess file, then using lsearch, but dnsbl is super-fast and there's many of em to pick from.  <br><br>I use several dnsbl's for my sendmail config, works quite well.&lt;/offtopic&gt;<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Wed Mar 07, 2007 1:55 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2007-03-06T19:56:07-04:00</updated>

		<published>2007-03-06T19:56:07-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71049#p71049</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71049#p71049"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71049#p71049"><![CDATA[
I too would say using dnsbl lookups is the way togo..<br>By merely looking at the source of the page you wished to mine, makes it pretty obvious the author has no intention on making it easy for ppl to use some automated mining tool (inserting ramdom comments, switching between plain-text and &amp;nnn;-style for each digit and decimal, etc).<br>Although converting these into something usable should'nt be that hard, it surely indicates the service-provider don't want ppl mining it, and is prepared to do quite alot to prevent ppl from doing it...<br><br>Besides, dnsbl is pretty standardized these days.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Tue Mar 06, 2007 7:56 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-06T19:35:19-04:00</updated>

		<published>2007-03-06T19:35:19-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71047#p71047</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71047#p71047"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71047#p71047"><![CDATA[
I tested the proxycheck script too, seems like it worked to me (ip changed to protect the innocent =) :<br><br>[theentity(dcc)] [18:22] proxycheck: doing dns lookup on plns-pppoe.dsl.plns. to get IP<br><br>[theentity(dcc)] [18:22] proxycheck: plns-pppoe.dsl.plns. resolves to x.x.x.x.<br><br>[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in torserver.tor.dnsbl.sectoor.de<br><br>[theentity(dcc)] [18:22] x.x.x.x not found in torserver.tor.dnsbl.sectoor.de<br><br>[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in cbl.abuseat.org<br><br>[theentity(dcc)] [18:22] x.x.x.x not found in cbl.abuseat.org<br><br>[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in opm.blitzed.org<br><br>[theentity(dcc)] [18:22] x.x.x.x not found in opm.blitzed.org<br><br>[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in dnsbl.ahbl.org<br><br>[theentity(dcc)] [18:22] x.x.x.x not found in dnsbl.ahbl.org<br><br>I put some putcmdlog lines into the script to see the above actions/results..  I used this in the proxycheck config:<br><br>set proxycheck_rbls { "torserver.tor.dnsbl.sectoor.de" "cbl.abuseat.org" "opm.blitzed.org" "dnsbl.ahbl.org" }<br><br>If those dnsbl's don't work for you, google TOR dnsbl, there are others to pick from. All you need is a dnsbl to use the proxycheck script.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Tue Mar 06, 2007 7:35 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Callisto]]></name></author>
		<updated>2007-03-06T19:06:54-04:00</updated>

		<published>2007-03-06T19:06:54-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71046#p71046</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71046#p71046"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71046#p71046"><![CDATA[
<blockquote class="uncited"><div>he has to many tor proxys i tryed.</div></blockquote>you tried what? tor proxies dnsbl's are pretty well up to date. I used just 1 that you listed and got this result. <br>OpmLongshanks check c-24-21-172-176.hsd1.mn.comcast.net <br>[22:50:45] &lt;OpmLongshanks&gt; CHECK -&gt; Checking '24.21.172.176' for open proxies []<br>[22:50:45] &lt;OpmLongshanks&gt; CHECK -&gt; DNSBL -&gt; 24.21.172.176 does not appear in BL zone dnsbl.njabl.org<br>[22:50:45] &lt;OpmLongshanks&gt; CHECK -&gt; DNSBL -&gt; 24.21.172.176 does not appear in BL zone opm.blitzed.org<br><strong class="text-strong">[22:50:45] &lt;OpmLongshanks&gt; CHECK -&gt; DNSBL -&gt; 24.21.172.176 appears in BL zone tor.dnsbl.sectoor.de (Tor exit server)</strong><br>[22:50:45] &lt;OpmLongshanks&gt; CHECK -&gt; All tests on 24.21.172.176 completed.<br><br>Check at <a href="http://jamesoff.net/site/projects/eggdrop-scripts/proxycheck/" class="postlink">http://jamesoff.net/site/projects/eggdr ... roxycheck/</a><br><br>And<br><a href="http://www.sectoor.de/tor.php#en-usage" class="postlink">http://www.sectoor.de/tor.php#en-usage</a><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=6064">Callisto</a> — Tue Mar 06, 2007 7:06 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[sdays]]></name></author>
		<updated>2007-03-06T18:37:53-04:00</updated>

		<published>2007-03-06T18:37:53-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71044#p71044</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71044#p71044"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71044#p71044"><![CDATA[
he has to many tor proxys i tryed.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8306">sdays</a> — Tue Mar 06, 2007 6:37 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Callisto]]></name></author>
		<updated>2007-03-06T11:16:13-04:00</updated>

		<published>2007-03-06T11:16:13-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71038#p71038</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71038#p71038"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71038#p71038"><![CDATA[
A search for tor detection or just tor on the forum would have found you this post<br><a href="http://forum.egghelp.org/viewtopic.php?t=10626&amp;highlight=" class="postlink">http://forum.egghelp.org/viewtopic.php? ... highlight=</a><br><br>however if the network uses any form of hostmasking then you cant really use a dnsbl search script.<br><br>Good luck<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=6064">Callisto</a> — Tue Mar 06, 2007 11:16 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[sdays]]></name></author>
		<updated>2007-03-06T06:30:34-04:00</updated>

		<published>2007-03-06T06:30:34-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71034#p71034</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71034#p71034"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71034#p71034"><![CDATA[
Both ip and hostname, tor proxys has hostnames and some dont...<br><br>* g695239 (~7HX8EW@69.55.232.152) has joined<br>* g695239 was kicked by Evi1Bot (drone)<br>* Evi1Bot sets mode: +b *!*@69.55.232.152<br>* c273508 (~<a href="mailto:3o3@c-24-21-172-176.hsd1.mn.comcast.net">3o3@c-24-21-172-176.hsd1.mn.comcast.net</a>) has joined<br>* c273508 was kicked by Evi1Bot (drone)<br>* Evi1Bot sets mode: +b *!*@c-24-21-172-176.hsd1.mn.comcast.net<br><br>all the proxys he use comes from <a href="http://proxy.org/tor.shtml" class="postlink">http://proxy.org/tor.shtml</a> thats why i need the bot go to the website and put all of them in the blacklist perm<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8306">sdays</a> — Tue Mar 06, 2007 6:30 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2007-03-06T06:03:25-04:00</updated>

		<published>2007-03-06T06:03:25-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=71032#p71032</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=71032#p71032"/>
		<title type="html"><![CDATA[get tor proxys from website and put them in blacklist...]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=71032#p71032"><![CDATA[
Question: Does the spammer show an ip or a hostname (need to know whether hostnames need to be reverse-resolved into ip for checking against the list.)<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Tue Mar 06, 2007 6:03 am</p><hr />
]]></content>
	</entry>
	</feed>
