<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/15262" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2008-02-23T20:19:44-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/15262</id>

		<entry>
		<author><name><![CDATA[Serban]]></name></author>
		<updated>2008-02-23T20:19:44-04:00</updated>

		<published>2008-02-23T20:19:44-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=81106#p81106</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=81106#p81106"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=81106#p81106"><![CDATA[
i had the same issue,<br>thing is bot ping timeout's after the "Attacker" uses him.<br>i run a botnet for 5 years now...keep my accs clean and stuff no stupid hosts no nothing. the log is clean, it just doesent show anything happening and yet my eggdrop is opping unknown nicks...<br><br>the REALLY BAD thing is i had the same problem with an emech...on another chan... really there is no problem with hosts, chanfix, etc<br><br>i heard they can access psybnc too, but it didnt happen to me...<br>WTF?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7045">Serban</a> — Sat Feb 23, 2008 8:19 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[nml375]]></name></author>
		<updated>2008-01-27T10:36:54-04:00</updated>

		<published>2008-01-27T10:36:54-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80383#p80383</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80383#p80383"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80383#p80383"><![CDATA[
One thing that passed my mind, is that the normal bitch-mode does not trigger when the opper is identified as a bot or master. With superbitch.tcl there are a few settings to alter it's behaviour:<ul><li><strong class="text-strong">sb_canop</strong>  (default: "m|m")<br>The flags for users who are allowed to give op to users with the flags specified in sb_canopflags.<br><br><span style="text-decoration:underline">Valid settings:</span> set in globalflags|chanflags format (e.g. "m|m" means global OR channel master, "m|-" means global masters only), or set to "" to specify that no users are allowed to op.</li><li><strong class="text-strong">sb_canopflags</strong>  (default: "o|o")<br>The flags for users who are allowed to be opped by users with an sb_canop flag.<br><br><span style="text-decoration:underline">Valid settings:</span> set in globalflags|chanflags format (e.g. "m|m" means global OR channel master, "m|-" means global masters only), or set to "" to specify that no users are allowed to be opped.</li><li><strong class="text-strong">sb_canopany</strong>  (default: "b|-")<br>The flags for users who are allowed to give op to anyone. This setting ignores sb_canop and sb_canopflags (e.g. you can set sb_canop to "" but users with flags specified in sb_canopany will still be allowed to op anyone).<br><br><span style="text-decoration:underline">Valid settings:</span> set in globalflags|chanflags format (e.g. "m|m" means global OR channel master, "m|-" means global masters only), or set to "" to specify that no users have the 'can op anyone' privilege.</li></ul>Bitchxpack does no deopping or such, all it does it try to camouflage your bot as a BitchX client. Since you use server-side Silence, it would'nt be doing much at all (all it does is give bX-like ctcp-replies). <br><br>As for seeing things on the partyline, you'd be best off being logged onto the actual bot doing the opping. Also, as I believe I mentioned before, using the .channel command helps seeing who's identified as what.<br><br>In any case, from what you (and others) have explained 'bout those modes, the only way for anyone to access your bot would've been through telnet. If I understood you correctly, you've set up some firewall rules to prevent others from accessing the telnet-ports? If this indeed helps, it would further indicate this being an issue with telnet-ports..<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8052">nml375</a> — Sun Jan 27, 2008 10:36 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[alekleet]]></name></author>
		<updated>2008-01-27T00:53:05-04:00</updated>

		<published>2008-01-27T00:53:05-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80378#p80378</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80378#p80378"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80378#p80378"><![CDATA[
hey imdeath thank you <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy"> now i dont have problems , i access my botnet via telnet i have too telnet-protect so jus i can access the via telnet. when that guy get @ last time i have the script bitchxpack (if anyone give op the bots make deop to +o and +o-ed) and + .netcahnset +bitchx but he get op without any problem , i was on the chat with the hub and i didnt see nothing. anyways thank you all .<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9634">alekleet</a> — Sun Jan 27, 2008 12:53 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[iamdeath]]></name></author>
		<updated>2008-01-25T08:04:31-04:00</updated>

		<published>2008-01-25T08:04:31-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80330#p80330</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80330#p80330"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80330#p80330"><![CDATA[
Sorry for jumping in when seniors are already suggesting and can suggest better than I could. Anyway I thought to share a few of my thoughts maybe this could help the owner of this post.<br><br>I am basically a user from Undernet network, I have a channel with has no X so a friend of mine has lended me a botnet to protect my @op. The botnet consist of 8-10 bots. There is nothing special about those bot they're as simple as any. But there are 2 botnet files we're using on every eggdrop. Here are those files:<br><br><a href="http://cricket.etherfast.ro/TCL/botnet.tcl" class="postlink">File 1</a><br><a href="http://cricket.etherfast.ro/TCL/botnet1.tcl" class="postlink">File 2</a><br><br>Not only that we also use silence on each bot, each means all the passive bots are using Silence not the hub bot. If all the bots have silence then how can we access the botnet? ehh<br><div class="codebox"><p>Code: </p><pre><code>putquick "SILENCE +*,~*@undernet.org,~*@*.undernet.org"putquick "SILENCE *"</code></pre></div>using that silence code will allow only users who are logged in X can access the bot, those who are not auth`d or logged in X will not be able to communicate with the bot. So in a way your bots become a lil secure from any kind of flood attacks. Usually flood comes from drones/floodbots which are not logged in X. So that command is quiet helpfull to protect your bots.<br><br>Another thing, add these two lines at the bottom of your config file. This will not allow anyone adding their host knowing the password. For example, if a friend of mine knows my password of bot but he/she does'nt have his/her *!*@host added in the bot. So through the addhost command he/she can easily add the host and get in the DCC and mess with everything. So if you unbind it, the bot will not react on this command. We use it on all the bots to protect ourself from adding host even if someone knows the password. If any op wants to add their host, we verify everything we find out we investigate then we add host. Which is quiet Secure.<br><br>I will also recommend you DO <span style="color:red">*NOT* </span>, I repeat maybe you did'nt read <span style="color:red"><span style="text-decoration:underline"><strong class="text-strong">DO NOT</strong></span></span> add anyone with auto op flag. I've experienced it, it is way insecure to give anyone auto op flags. How hard is it for someone to perform: /msg botnick OP password?. So there is no point of giving someone +a chattr. <br><br>Also use strictop mode and use any good +bitch or strictop script, you can ffind them from <a href="http://www.egghelp.org/tcl.htm" class="postlink">Archive</a> easily.<br><br>These are minor things but if you follow them all, you will neverbecome opless. <br><br>If still there is something left do let me know.<br><br>peace<br>iamdeath<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=5982">iamdeath</a> — Fri Jan 25, 2008 8:04 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Alchera]]></name></author>
		<updated>2008-01-24T21:04:35-04:00</updated>

		<published>2008-01-24T21:04:35-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80323#p80323</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80323#p80323"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80323#p80323"><![CDATA[
<blockquote class="uncited"><div>i`m not retarded. that guy gets @ from my eggdrops,</div></blockquote>No one said you were. <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_rolleyes.gif" width="15" height="15" alt=":roll:" title="Rolling Eyes"><br><br>Secure shell? Channel passes (in scripts) secured?<br><br><strong class="text-strong">Wipe</strong> the user file and <span style="text-decoration:underline">delete</span> the backup. <strong class="text-strong">Wipe</strong> the channel access list(s). <strong class="text-strong">Change</strong> the eggdrops nick pass and <em class="text-italics">manually</em> identify it to services.<br><br>It's <strong class="text-strong">not</strong> an eggdrop bug/hack.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3646">Alchera</a> — Thu Jan 24, 2008 9:04 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Zircon]]></name></author>
		<updated>2008-01-24T17:49:38-04:00</updated>

		<published>2008-01-24T17:49:38-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80317#p80317</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80317#p80317"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80317#p80317"><![CDATA[
<blockquote class="uncited"><div><div class="codebox"><p>Code: </p><pre><code>in the mode +x and +d, and silence to everyone ? </code></pre></div>yes.</div></blockquote>  Well, in this case, i doubt it has any utility to prevent hacking, coz :<br><strong class="text-strong">First :</strong> +x is a usermode that allow logged in users to hide their real host, replacing it with @username.users.undernet.org, it does nothing more.<br><strong class="text-strong">Second :</strong> +d will allow your bot to not "hear" a thing that's said in the channels. Private messages get through. And you can see join/part/kick and change mode in the channel.<br><strong class="text-strong">Third :</strong> /Silence will prevent your bot from receiving any private/notice/ctcp message.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8115">Zircon</a> — Thu Jan 24, 2008 5:49 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[alekleet]]></name></author>
		<updated>2008-01-24T17:38:12-04:00</updated>

		<published>2008-01-24T17:38:12-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80316#p80316</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80316#p80316"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80316#p80316"><![CDATA[
<div class="codebox"><p>Code: </p><pre><code>in the mode +x and +d, and silence to everyone ? </code></pre></div><br>yes.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9634">alekleet</a> — Thu Jan 24, 2008 5:38 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Zircon]]></name></author>
		<updated>2008-01-24T17:33:47-04:00</updated>

		<published>2008-01-24T17:33:47-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80315#p80315</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80315#p80315"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80315#p80315"><![CDATA[
Hi there<br><br>   Just curious, what do you mean by "bots +x +d and +silence". Do you mean  that the bots are in the mode +x and +d, and silence to everyone ? or you mean that the bots logs "d" events (d - misc debug information) ans "x" events ( x - file transfers and file-area commands ) ? and what +silence mean ? I think it s important to know his procesus of hackin, for preventing it in future, for you, and for every1 here.<br>   I have a big doubt about the ability of this person to hack any of my channels  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8115">Zircon</a> — Thu Jan 24, 2008 5:33 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[alekleet]]></name></author>
		<updated>2008-01-24T16:57:31-04:00</updated>

		<published>2008-01-24T16:57:31-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80314#p80314</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80314#p80314"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80314#p80314"><![CDATA[
i`m not retarded. that guy gets @ from my eggdrops, no via server or chanfix (C) all my users on the eggdrops are trusted. last time when he get @ i was on chat and i didnt see any command for takein @ like .op nick #cc-power t.s i didnt see nothing there. and yeah now i have new eggnet with logged bots +x +d and +silence and telnet protect. i dont have now problems but that guy can take anychannel he want take it. u can close this teme now. thanks for the help and all posts. i`ll continue use this forum coz its nice one.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9634">alekleet</a> — Thu Jan 24, 2008 4:57 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Alchera]]></name></author>
		<updated>2008-01-23T01:07:04-04:00</updated>

		<published>2008-01-23T01:07:04-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80281#p80281</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80281#p80281"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80281#p80281"><![CDATA[
<span style="color:darkred">Suggestion</span> for alekleet: Completely <strong class="text-strong">wipe</strong> your channel access list(s).<br><br>One of your "trusted" ops has been clumsy with his pass by the looks of all this.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3646">Alchera</a> — Wed Jan 23, 2008 1:07 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Zircon]]></name></author>
		<updated>2008-01-22T13:31:36-04:00</updated>

		<published>2008-01-22T13:31:36-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80264#p80264</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80264#p80264"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80264#p80264"><![CDATA[
Before looking for a possible bug/hack, i think we should start by being sure it s not a problem related to Channel Fix, or to an IRCOP, or just due to the limited knowledge of the user to manage efficiently his bot. alekleet, start by enabling the log of the channel...I hope you know how to do that....<br>By the way, what s the name of your channel ?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=8115">Zircon</a> — Tue Jan 22, 2008 1:31 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[YooHoo]]></name></author>
		<updated>2008-01-22T09:59:23-04:00</updated>

		<published>2008-01-22T09:59:23-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80261#p80261</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80261#p80261"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80261#p80261"><![CDATA[
<blockquote class="uncited"><div>where i can find packet sniffer ? can anyone from here help me ?</div></blockquote>try google  <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_eek.gif" width="15" height="15" alt=":shock:" title="Shocked"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2706">YooHoo</a> — Tue Jan 22, 2008 9:59 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[rosc2112]]></name></author>
		<updated>2008-01-22T07:51:28-04:00</updated>

		<published>2008-01-22T07:51:28-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80256#p80256</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80256#p80256"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80256#p80256"><![CDATA[
Again, if you are not able to learn and figure this stuff out, you should not be running eggdrop. <br><br>If anyone here really believed there was some kind of remote exploit in the current eggdrop, we would ALL be running packet sniffers to figure out what is broke.  But..We don't and so we're not.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=7395">rosc2112</a> — Tue Jan 22, 2008 7:51 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Alchera]]></name></author>
		<updated>2008-01-21T23:22:06-04:00</updated>

		<published>2008-01-21T23:22:06-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80245#p80245</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80245#p80245"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80245#p80245"><![CDATA[
<blockquote class="uncited"><div> so please help me with direkt link for download , installin and run it if u can</div></blockquote>Suddenly cannot read?<br><br>Which clickable link do you not understand? The "GetHelp" one?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3646">Alchera</a> — Mon Jan 21, 2008 11:22 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[alekleet]]></name></author>
		<updated>2008-01-21T23:09:17-04:00</updated>

		<published>2008-01-21T23:09:17-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=80244#p80244</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=80244#p80244"/>
		<title type="html"><![CDATA[eggdrop hacking]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=80244#p80244"><![CDATA[
i never used something like this so please help me with direkt link for download , installin and run it if u can<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=9634">alekleet</a> — Mon Jan 21, 2008 11:09 pm</p><hr />
]]></content>
	</entry>
	</feed>
