Exploits Team Pages
x

Ident FAQ
Windows Ident
Macintosh Ident
Unix Ident
Microsoft ICS
Proxies & Firewalls
Routers
Security Check
Akill Information
Specific Fixes
Contact Us

Stop Messenger Spam. Free & Easy. Click Here

Exploits Autokill Information

Select the Autokill code affecting you from the list below for additional information.

DALnet's exploits team strongly recommend that you do not accept unsolicited files on IRC. While not all files are harmful, the vast majority of unsolicited sends are malicious and should not be accepted. We also strongly recommend that all users run recently updated anti-virus software at all times. If you don't have an anti-virus package, see http://www.antivirus.com for a reasonably effective one.

You should also consider running a personal firewall to protect your PC if you make use of IRC regularly. We recommend the Tiny Personal Firewall for all windows users as it's easy to install and configure. The Tiny Personal Firewall is free for personal use.

You can find further advise on securing your computer on the CERT website, follow this link to go directly there : http://www.cert.org/tech_tips/home_networks.html

Note to all users : DALnet's exploits team takes all reasonable care to ensure the accuracy of any autokills we set, however the increasing use of dynamic IP addressing can result in some users being incorrectly affected by an autokill. All explanations on this page are relevant only to the user(s) assigned a specific IP address at the time when the autokill was set and should not be considered definitive. DALnet is a private network and reserves the right to deny access to anyone for any reason and without explanation. Autokills are coded based on our assessment of a given situation at the time the autokill was placed. Such coding is intended solely as a guide to assist IRC operators and users identify the potential reason for an autokill and does not indicate or imply any wrongdoing on the part of any specific user.

If you believe you are wrongly affected by a ban due to dynamic IP addressing, please complete the contact from giving the autokill ID number (in the disconnection message) and including the output of IPCONFIG /ALL. We will review the IPCONFIG details and will remove the ban if we believe it is no longer valid. Please note because we check all such requests manually the process may take up to 72 hours to complete.


[Exp/Aplore]
Nominal Duration : 48 Hours
User Action : Update your Anti-Virus utility.
Your system may be infected by the w32.aplore@mm worm. Please update your anti-virus utility and run a full scan to detect and if necessary remove this worm. Further information about it and it's effects can be found on http://securityresponse.symantec.com/avcenter/venc/data/w32.aplore@mm.html

[Exp/Trojan]
Nominal Duration : Permanent
User Action : Follow the instructions below to reconnect.

Your PC may be infected by a virus or trojan horse program. If found you will need to remove the trojan and re-install your IRC client to reconnect to DALnet. You can obtain a freeware trojan scanner from Lockdown or you can use a modern anti-virus utility to detect and remove most trojans. Please be sure to update whichever program you use with the latest definition files from the manufacturer.

[Exp/Fldhst]
Nominal Duration : 3 days to One Week
User Action : Secure your machine and wait for the ban to expire.

This IP address or IP block has possibly been involved in flooding attacks against our network. This is often the result of downloading files from untrusted sources which are infected with one of several trojan horse programs. Again, we recommend the use of a trojan scanner or modern anti-virus utility to detect and if necessary remove the trojan. These autokills normally last for no more than one week, although they may be extended if the machines are not secured during that period.

[Exp/Os]
Nominal Duration : 12 Hours normally, may be extended in extreme situations.
User Action : Secure your machine and wait for the ban to expire.

This IP or IP block has possibly been involved in distributed Denial of Service attacks against our network. This can be caused by downloading files from untrusted sources which are infected with one of several DDoS client programs. We recommend the use of a trojan scanner or modern anti-virus utility to search for and if necessary remove the trojan. These autokills normally last for no more than 12 hours, although they will be extended if the machines are not secured.

For further help with this problem, click here.

[Exp/Comp]
Nominal Duration : 3 days to One Week
User Action : Secure your machine and wait for the ban to expire.
Your machine may have been compromised and be advertising it's presence on IRC. Information stored on your PC may be available to unauthorised persons as a result of this security breach. Please check for trojans, viruses and compromised scripts. You can find a freeware trojan scanner from Lockdown Corp. here which may help locate and remove the trojan.

[Exp/Clone]
Nominal Duration : 30 minutes to One Week
User Action : Wait for the ban to expire.

Please do not load clones onto DALnet. A clone is considered anything over ONE connection, although DALnet will allow a maximum of 2 clients.

[Exp/Roe]
Nominal Duration : Permanent
User Action : Follw the instructions below to reconnect.

For security reasons we do not permit users to connect to IRC as the ROOT user from unix systems. Please create a normal user account (preferably without enhanced permissions) and use that when connecting to DALnet. Users of windows who recieve this message need to change their ident setting as described in the Windows Ident section of this site.

[Exp]
Nominal Duration : Permanent
User Action : Contact your service provider.

This host is no longer welcome on DALnet. If you recieve this message from multiple IP addresses or hostnames it is probable that your domain has been banned. Please ask your service provider for further information in this case.

[Exp/Ma]
Nominal Duration : 30 Minutes to One Week
User Action : Follow the instructions below and wait for the ban to expire.

Your machine may have been infected by trojan horse which advertises one of several websites on DALnet. You should run a full scan of your system using a recently updated virus scanner or a dedicated anti-trojan package such as Swat-It to detect and if necessary remove the trojan. When you have done this, wait for the ban to expire then reconnect to DALnet.

[Exp/script]
Nominal Duration : Permanent
User Action : Follow the instructions below.

Some scripts are abusive in nature and have been banned from DALnet. Usually these are 'war scripts' (Polaris, Seventh Sphere etc.), advertising scripts (X-Inviter, IRCAP) or clone scripts. You will need to remove the script and reset your ident as described in the ident FAQ to reconnect to DALnet.

Some users may find they are banned with this message even though they do not run one of the above scripts. In this case, please reset your ident as described in the ident FAQ to reconnect.


© DALnet IRC Network 2003.
DALnet treats copyright violation extremely seriously.
You are expressly forbidden to copy, mirror or otherwise duplicate the content, style or look and feel of these pages without express written permission from an authorized DALnet official. Copyright violators will be dealt with severly.