<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/20652" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2019-08-04T03:31:18-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/20652</id>

		<entry>
		<author><name><![CDATA[caesar]]></name></author>
		<updated>2019-08-04T03:31:18-04:00</updated>

		<published>2019-08-04T03:31:18-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=107740#p107740</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=107740#p107740"/>
		<title type="html"><![CDATA[Telnet connection flood ignores]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=107740#p107740"><![CDATA[
Open up your eggdrop.conf file and at 'BOTNET/DCC/TELNET' section tell us what did you set on the 'listen' line? 'listen 3333 all' or something like this?<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=187">caesar</a> — Sun Aug 04, 2019 3:31 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[willyw]]></name></author>
		<updated>2019-08-03T07:52:28-04:00</updated>

		<published>2019-08-03T07:52:28-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=107738#p107738</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=107738#p107738"/>
		<title type="html"><![CDATA[Re: Telnet connection flood ignores]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=107738#p107738"><![CDATA[
Do you own the server that the bot is on?      Are you root?<br><br>If so, do you know how to use iptables ?<br><br>I have only barely scratched the surface with iptables, and that was some time ago.    It is very powerful, and highly configurable.   You can easily make a mess of it, and block people that you don't want to be blocked, including yourself.<br><br>However, if you study it, it is a very useful tool.<br><br>With it, I'm thinking that you can block an ip or range of ips.    If you do it at this level, the bot won't even ever see the incoming traffic at all.<br><br>Just a thought....<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10420">willyw</a> — Sat Aug 03, 2019 7:52 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[willyw]]></name></author>
		<updated>2019-08-03T07:46:56-04:00</updated>

		<published>2019-08-03T07:46:56-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=107737#p107737</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=107737#p107737"/>
		<title type="html"><![CDATA[Re: Telnet connection flood ignores]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=107737#p107737"><![CDATA[
<blockquote class="uncited"><div>...<br>Have tried using +ignore but they eventually time out - is there a way to place a perm ignore on an address or set of addresses...such as that first 185 one or the steadfastdns.net one?<br>...</div></blockquote>Some months ago, I was getting it on a couple bots, too.  Not that bad though - it never caused a timeout.<br><br>I discovered that if I put the address on ignore for about a week, that was enough.  By the time the ignore expired,  they had stopped.    One day was not enough.<br><br>Anyway - just experimented with the ignore command, and it seems that 364 days is the maximum it will keep an ignore active.   <br>Try it.  Give it 1000 days.   It will save the ignore with 364.<br><br>The question for you is:  Isn't that enough?      <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><br><br>Also, look in eggdrop.conf.<br>Find:<br><div class="codebox"><p>Code: </p><pre><code># Define here how many telnet connection attempts in how many seconds from# the same host constitute a flood. The correct format is Attempts:Seconds.set telnet-flood 5:60</code></pre></div>This will cause the bot to automatically put them on ignore.    I just tested it - it works.  <br><br>What I don't understand is ( if you have left it at the default settings as shown above)  why - with the volume of telnet attempts and frequency of them that you have described -  why the bot is not automatically putting them on ignore all by itself.<br><br>Check that setting.  Maybe you have it off ?<br>And set it to something that you feel is appropriate.<br><br>The length ot time before such an ignore expires is controlled by:<br><div class="codebox"><p>Code: </p><pre><code># Set the time in minutes that temporary ignores should last.set ignore-time 15</code></pre></div>If you want automatic ignores to be longer, that's where you change that.<br><br><br>I hope this helps.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10420">willyw</a> — Sat Aug 03, 2019 7:46 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[NewzNZ]]></name></author>
		<updated>2019-08-03T06:23:15-04:00</updated>

		<published>2019-08-03T06:23:15-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=107736#p107736</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=107736#p107736"/>
		<title type="html"><![CDATA[Telnet connection flood ignores]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=107736#p107736"><![CDATA[
Hi<br><br>My bots have recently been getting flooded by Telnet connections such as:<br><br>[09:48:18] Telnet connection: 185.100.87.250/45920<br>[09:48:17] Telnet connection: ip231.208-100-26.static.steadfastdns.net/45518<br><br>...so many floods at a time that it causes the bots to Ping timeout.<br><br>(numbers after the / change with every connection attempt)<br><br>Have tried using +ignore but they eventually time out - is there a way to place a perm ignore on an address or set of addresses...such as that first 185 one or the steadfastdns.net one?<br><br>Thanks in advance.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=10525">NewzNZ</a> — Sat Aug 03, 2019 6:23 am</p><hr />
]]></content>
	</entry>
	</feed>
