| View previous topic :: View next topic |
| Author |
Message |
sdays Halfop
Joined: 21 Oct 2006 Posts: 98
|
Posted: Tue Mar 06, 2007 2:56 am Post subject: get tor proxys from website and put them in blacklist... |
|
|
Hi all i need a script that gets the proxys from http://proxy.org/tor.shtml and i want it blacklist in /db/blacklist.txt
i need this script a spammer that use tor proxys wont go away and this is the only way so please help thanks. |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Tue Mar 06, 2007 6:03 am Post subject: |
|
|
| Question: Does the spammer show an ip or a hostname (need to know whether hostnames need to be reverse-resolved into ip for checking against the list.) |
|
| Back to top |
|
 |
sdays Halfop
Joined: 21 Oct 2006 Posts: 98
|
Posted: Tue Mar 06, 2007 6:30 am Post subject: |
|
|
Both ip and hostname, tor proxys has hostnames and some dont...
* g695239 (~7HX8EW@69.55.232.152) has joined
* g695239 was kicked by Evi1Bot (drone)
* Evi1Bot sets mode: +b *!*@69.55.232.152
* c273508 (~3o3@c-24-21-172-176.hsd1.mn.comcast.net) has joined
* c273508 was kicked by Evi1Bot (drone)
* Evi1Bot sets mode: +b *!*@c-24-21-172-176.hsd1.mn.comcast.net
all the proxys he use comes from http://proxy.org/tor.shtml thats why i need the bot go to the website and put all of them in the blacklist perm |
|
| Back to top |
|
 |
Callisto Halfop
Joined: 13 Mar 2005 Posts: 86
|
Posted: Tue Mar 06, 2007 11:16 am Post subject: |
|
|
A search for tor detection or just tor on the forum would have found you this post
http://forum.egghelp.org/viewtopic.php?t=10626&highlight=
however if the network uses any form of hostmasking then you cant really use a dnsbl search script.
Good luck |
|
| Back to top |
|
 |
sdays Halfop
Joined: 21 Oct 2006 Posts: 98
|
Posted: Tue Mar 06, 2007 6:37 pm Post subject: |
|
|
| he has to many tor proxys i tryed. |
|
| Back to top |
|
 |
Callisto Halfop
Joined: 13 Mar 2005 Posts: 86
|
Posted: Tue Mar 06, 2007 7:06 pm Post subject: |
|
|
| sdays wrote: | | he has to many tor proxys i tryed. |
you tried what? tor proxies dnsbl's are pretty well up to date. I used just 1 that you listed and got this result.
OpmLongshanks check c-24-21-172-176.hsd1.mn.comcast.net
[22:50:45] <OpmLongshanks> CHECK -> Checking '24.21.172.176' for open proxies []
[22:50:45] <OpmLongshanks> CHECK -> DNSBL -> 24.21.172.176 does not appear in BL zone dnsbl.njabl.org
[22:50:45] <OpmLongshanks> CHECK -> DNSBL -> 24.21.172.176 does not appear in BL zone opm.blitzed.org
[22:50:45] <OpmLongshanks> CHECK -> DNSBL -> 24.21.172.176 appears in BL zone tor.dnsbl.sectoor.de (Tor exit server)
[22:50:45] <OpmLongshanks> CHECK -> All tests on 24.21.172.176 completed.
Check at http://jamesoff.net/site/projects/eggdrop-scripts/proxycheck/
And
http://www.sectoor.de/tor.php#en-usage |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Tue Mar 06, 2007 7:35 pm Post subject: |
|
|
I tested the proxycheck script too, seems like it worked to me (ip changed to protect the innocent =) :
[theentity(dcc)] [18:22] proxycheck: doing dns lookup on plns-pppoe.dsl.plns. to get IP
[theentity(dcc)] [18:22] proxycheck: plns-pppoe.dsl.plns. resolves to x.x.x.x.
[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in torserver.tor.dnsbl.sectoor.de
[theentity(dcc)] [18:22] x.x.x.x not found in torserver.tor.dnsbl.sectoor.de
[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in cbl.abuseat.org
[theentity(dcc)] [18:22] x.x.x.x not found in cbl.abuseat.org
[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in opm.blitzed.org
[theentity(dcc)] [18:22] x.x.x.x not found in opm.blitzed.org
[theentity(dcc)] [18:22] proxycheck: looking up x.x.x.x in dnsbl.ahbl.org
[theentity(dcc)] [18:22] x.x.x.x not found in dnsbl.ahbl.org
I put some putcmdlog lines into the script to see the above actions/results.. I used this in the proxycheck config:
set proxycheck_rbls { "torserver.tor.dnsbl.sectoor.de" "cbl.abuseat.org" "opm.blitzed.org" "dnsbl.ahbl.org" }
If those dnsbl's don't work for you, google TOR dnsbl, there are others to pick from. All you need is a dnsbl to use the proxycheck script. |
|
| Back to top |
|
 |
nml375 Revered One
Joined: 04 Aug 2006 Posts: 2857
|
Posted: Tue Mar 06, 2007 7:56 pm Post subject: |
|
|
I too would say using dnsbl lookups is the way togo..
By merely looking at the source of the page you wished to mine, makes it pretty obvious the author has no intention on making it easy for ppl to use some automated mining tool (inserting ramdom comments, switching between plain-text and &nnn;-style for each digit and decimal, etc).
Although converting these into something usable should'nt be that hard, it surely indicates the service-provider don't want ppl mining it, and is prepared to do quite alot to prevent ppl from doing it...
Besides, dnsbl is pretty standardized these days. _________________ NML_375, idling at #eggdrop@IrcNET |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Wed Mar 07, 2007 1:55 am Post subject: |
|
|
| nml375 wrote: | Although converting these into something usable should'nt be that hard, it surely indicates the service-provider don't want ppl mining it, and is prepared to do quite alot to prevent ppl from doing it...
Besides, dnsbl is pretty standardized these days. |
In their defense, they do provide an .htaccess formatted file, but, why bother making a new script when dnsbl+proxyscan will do the job infinitely faster than any other method I could think of? I was thinking of pulling the data from the htaccess file, then using lsearch, but dnsbl is super-fast and there's many of em to pick from.
I use several dnsbl's for my sendmail config, works quite well.</offtopic> |
|
| Back to top |
|
 |
silverboy Halfop
Joined: 11 Feb 2006 Posts: 55
|
Posted: Wed Mar 07, 2007 1:56 am Post subject: |
|
|
ban ?1*!~*@* ?2*!~*@* ?3*!~*@* ?4*!~*@* ?4*!~*@* ?5*!~*@* ?6*!~*@* ?7*!~*@* ?8*!~*@* ?9*!~*@* and no nicks like that will join your channel.
if ur doin it the other way eggdrop is damn slower.! _________________ proxyz..proxyz...i see everywher... O_o |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Wed Mar 07, 2007 2:26 am Post subject: |
|
|
| silverboy wrote: | | if ur doin it the other way eggdrop is damn slower.! |
proxyscan.tcl looked pretty fast to me.. Anyone care to use [time] on it and find out exactly how many milliseconds it takes to get the info from a half dozen dnsbl's with it? If I had to guess, I'd say it took maybe 1/100th of a sec to look up the test IP I tried in the 5 dnsbl's..
Of course, there's always the possibility that one of the dnsbl servers doesn't respond immediately, and I already deleted the proxyscan script, so I dont know offhand if/how it handles timeouts.
Considering that it does the query in 1 one proc and handles the response in a separate proc, I don't see any reason it would lag the bot. I suppose the join bind might lag the bot if the channel is extremely busy, but dnsbl lookups as done in proxyscan.tcl is a damn sight faster than the method I had in mind =) |
|
| Back to top |
|
 |
silverboy Halfop
Joined: 11 Feb 2006 Posts: 55
|
Posted: Thu Mar 08, 2007 2:13 am Post subject: |
|
|
does the Proxyscan.tcl detec Socks4 as well?
where can i get to download this one. _________________ proxyz..proxyz...i see everywher... O_o |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Thu Mar 08, 2007 3:09 pm Post subject: |
|
|
| If there is a sock4 dnsbl, sure.. Try google searching for "socks4 dnsbl" and the link for proxyscan was posted in this thread, or just search the tcl archive for proxyscan, it's in the archive. |
|
| Back to top |
|
 |
silverboy Halfop
Joined: 11 Feb 2006 Posts: 55
|
Posted: Fri Mar 09, 2007 11:01 pm Post subject: |
|
|
| Code: | | variable banport "1080,1081,3380,3381" ;# Most commen port list |
it does kick. socks 4 common port = 1080
or does it only kick this port list? if so can i add some more ports to it...
between the tcl sends warning to the users via NOTICE, how to disable this?
shud i remove these lines?
| Code: | | putserv "NOTICE $nick :$warnmsg" |
_________________ proxyz..proxyz...i see everywher... O_o |
|
| Back to top |
|
 |
rosc2112 Revered One

Joined: 19 Feb 2006 Posts: 1454 Location: Northeast Pennsylvania
|
Posted: Sat Mar 10, 2007 1:29 am Post subject: |
|
|
| If the variable banport is in the proxycheck script, yes you can add more to it, I dont have the script any longer to look at it, and for your 2nd question, yes you can comment out the putserv line or delete if you prefer to stop sending kick notices to the users. |
|
| Back to top |
|
 |
|