CBL/K-lined/... on all EFnet IRC servers because of "a windows trojan" on a Linux machine...

Help with EFnet related issues

Moderators: Website/Forum Admins, EFnet/Help Moderators

Kehlyos
Posts: 1
Joined: Wed May 27, 2015 10:22 pm

CBL/K-lined/... on all EFnet IRC servers because of "a windows trojan" on a Linux machine...

Postby Kehlyos » Wed May 27, 2015 10:49 pm

Hello guy's,
Here's my problem:
Every 3-5 days I am banned of the EFnet servers, all of them.
I am of course listed on CBL, EfnetCBL and every other *CBL.
It always says the same thing, I am infected by Zeus, a botnet, trojan, god knows what thing.
The first time I saw the message I was laughing a bit, I use Linux and those botnets/trojans security concerns never concerns me, so I discarded the message.

I started to receive it every 3-5 days and looked into it.
Of course it WAS NOT MY SYSTEM, this trojan only affects windows, nothing else.
So I discarded it againg, always de-banning me every time I saw it.
Today, I reconnect to EFnet and I see that I am K-lined or just "banned" or what ever until I finally found an irc server telling me I am CBL listed.

It's a quite annoying thing to de -ban myself from CBL every time I want to use IRC (except exceptions, I go on IRC every week/day).
I am concerned by this situation and looked into it.
Here is the best answer I could come up with and I actuall verified all my claims:

My IRC is not cool, and not well funded, they have a "giant router" to route all our traffic, this gives birth to slow speeds and the ISP being a giant classical subnet as it does not have a dhcp server.

My hypothesis is that someone on the network using windows got infected by this Zeus botnet and since all or at least a sizable amount of the ISP users have 1 ip, Efnet does not distinguish me from him and treats me the same way as if I was actually infected
Is there another explaination ?

Because if I think about it, there is no reason for Efnet to believe me and potentially compromise there security by de-banning me...
So what do I do ?
I already contacted my ISP, they don't give a sh*t and after a couple of calls and a visit I got put in touch with the "technichal team" who laughed at me for using IRC and have no plans, obviously to do something about upgrading there network...

Thank you for your help!
User avatar
Handle With Care
Posts: 181
Joined: Wed Oct 26, 2005 6:53 pm
Location: Southern California

Re: CBL/K-lined/... on all EFnet IRC servers because of "a windows trojan" on a Linux machine...

Postby Handle With Care » Thu May 28, 2015 6:48 pm

The full message gives you a URL to which to report the problem. Also need the full IP# banned.
EFnet IRC Network Forum Moderator
IRC Operator (IRCOp) irc.Prison.NET
Sic transit gloria mundi.
User avatar
munky
Site Admin
Posts: 826
Joined: Wed Jul 02, 2003 4:54 pm
Location: Phoenix AZ
Contact:

Re: CBL/K-lined/... on all EFnet IRC servers because of "a windows trojan" on a Linux machine...

Postby munky » Wed Jun 03, 2015 5:35 pm

if you're ISP is using a NAT, putting you on the same visible IP as someone infected with trojans/viruses, there's not a lot you can do with your own IP. however there are other methods of getting on IRC:
http://rbl.efnetrbl.org/FAQ/NAT-SharedIP/WhatCanIDo?
In God we trust,
Everyone else must have an X.509 certificate.

Return to “Help”

Who is online

Users browsing this forum: No registered users and 1 guest