K:lined

Help with EFnet related issues

Moderators: Website/Forum Admins, EFnet/Help Moderators

sdOK
Posts: 3
Joined: Wed Jan 11, 2006 3:14 pm

K:lined

Postby sdOK » Wed Jan 11, 2006 3:20 pm

I have been K:lined from efnet.
I logged in today and got immediately k:lined.
efnet.demon.co.uk- *** Banned Temporary K-line 1440 min. - DNSBL listed. Check ircnet.com/cgi-bin/bl.cgi?ip=85.210.42.212 for removal. (2006/1/11 13.23)
I check on that site and it says - IP Address 85.210.42.212 was found in the CBL.

It was detected at 2006-01-05 16:00 GMT (+/- 30 minutes).

A recent Sober worm variant is causing considerable havoc on the Internet. This particular variant sends out email allegedly from the FBI or CIA (amongst other things). It is known by anti-virus companies under several different names: Sober.U (eg: ClamAV), Sober.Z (eg: Sophos) and Sober.X (eg: Symantec).

I scanned for sober or any other virus and found nothing at all.
Can I find more info as I dont want to just get K:lined for another 24 hours without having any idea what is causing it.
JustHavinFun
Posts: 11
Joined: Wed Jan 11, 2006 5:07 pm

Postby JustHavinFun » Wed Jan 11, 2006 5:18 pm

Hi, I'm getting exactly the same problem.

Can this be sorted out please?
User avatar
lucy
Posts: 234
Joined: Wed Jul 02, 2003 6:22 pm
Location: graceland
Contact:

Postby lucy » Wed Jan 11, 2006 10:59 pm

did you go to the url listed in the kline message?
sdOK
Posts: 3
Joined: Wed Jan 11, 2006 3:14 pm

Postby sdOK » Thu Jan 12, 2006 11:06 am

yes and nothing has changed. I am still k:lined on most efnet servers.
I found one in israel that lets me on.
While i am on this server is there somewhere to get hold of ops?
User avatar
lucy
Posts: 234
Joined: Wed Jul 02, 2003 6:22 pm
Location: graceland
Contact:

Postby lucy » Thu Jan 12, 2006 1:44 pm

/stats p the server and it will tell you ircops on that server and their idle time
User avatar
munky
Site Admin
Posts: 826
Joined: Wed Jul 02, 2003 4:54 pm
Location: Phoenix AZ
Contact:

Postby munky » Thu Jan 12, 2006 1:52 pm

you have to do more than just visit the URL. you have to go to the URL and read the directions on how to request removal from the blacklist. since you are listed in cbl, visit http://cbl.abuseat.org

though, currently when i search the blacklists, that IP does not appear
In God we trust,
Everyone else must have an X.509 certificate.
sdOK
Posts: 3
Joined: Wed Jan 11, 2006 3:14 pm

Postby sdOK » Thu Jan 12, 2006 6:05 pm

No it must have been removed. I am not k:lined now.
Its a bit worrying though as I have changed nothing bar scanning my pc like mad looking for non existant trojans etc. I just use basic mirc with no scripts/bots. My pc is virus scanned every day.
I understand with the weight of people using efnet that it is impossible to keep track of every banned user but I did absolutely nothing. Just logged on and got k:lined. No explanation. Makes you wonder though. Have I upset somebody? Is someone out for me now? Was it just random fate singled me out?
User avatar
Pills
Forum Admin
Posts: 312
Joined: Wed Jul 02, 2003 1:14 pm
Location: Long Island, NY
Contact:

Postby Pills » Thu Jan 12, 2006 8:30 pm

You did nothing to anyone; your IP was listed on that list. It was looked up, and banned. No user (oper) involvement.
Last edited by Pills on Fri Jan 13, 2006 4:41 pm, edited 1 time in total.
admin, irc.umich.edu
oper, irc.servercentral.net
JustHavinFun
Posts: 11
Joined: Wed Jan 11, 2006 5:07 pm

Postby JustHavinFun » Thu Jan 12, 2006 10:09 pm

Hi guys I am still getting the kline: My ip is obviously contained withinn the list. When I go to the URL there are no instructions, just various options and info regarding my ip such as traceroute, host, domain. Sort of like dnsstuff.com

Any ideas?

Thanks
User avatar
munky
Site Admin
Posts: 826
Joined: Wed Jul 02, 2003 4:54 pm
Location: Phoenix AZ
Contact:

Postby munky » Fri Jan 13, 2006 12:52 pm

In God we trust,
Everyone else must have an X.509 certificate.
JustHavinFun
Posts: 11
Joined: Wed Jan 11, 2006 5:07 pm

Postby JustHavinFun » Sat Jan 14, 2006 2:57 am

My system is fine, I formatted it quite recently :/
JustHavinFun
Posts: 11
Joined: Wed Jan 11, 2006 5:07 pm

Postby JustHavinFun » Sat Jan 14, 2006 11:56 am

Hey, could somebody please assist me in this matter? I'm on a University network so it could play a small part although I'm not 100% sure.

Thanks :)
User avatar
lucy
Posts: 234
Joined: Wed Jul 02, 2003 6:22 pm
Location: graceland
Contact:

Postby lucy » Sat Jan 14, 2006 2:32 pm

did you scan your system like munky suggested?

have you gone to the server list and tried other servers?
wundr
Posts: 140
Joined: Sun Jul 06, 2003 11:34 pm
Location: Japan

Postby wundr » Sat Jan 14, 2006 5:03 pm

JustHavinFun wrote:Hey, could somebody please assist me in this matter? I'm on a University network so it could play a small part although I'm not 100% sure.

Thanks :)
It could play a large part if your uni has you on a NAT. This would mean that a number of people all use the same external IP, so if any of them have a virus, then you may get banned for it, too (because you are coming from the same IP). You can check this by going to Start-->Run, typing 'cmd', then in the box, ipconfig. If your IP is a 192.168.x.x or 10.x.x.x IP, then you are probably behind a NAT.

The blacklist's web site says it was last detected on January 12th, so your recent format may not have helped...

EDIT: The CBL's web site now says about your IP: "It was previously listed, but was removed at 2006-01-14 11:59 GMT"... seems you have been delisted successfully. Congrats!
JustHavinFun
Posts: 11
Joined: Wed Jan 11, 2006 5:07 pm

Postby JustHavinFun » Sun Jan 15, 2006 12:18 am

Brilliant... it works now :) ....

irc.efnet.nl

woohoo

Who is online

Users browsing this forum: No registered users and 2 guests