PtokaX forum

Stuff => Offtopic => Topic started by: Requiem on 20 January, 2005, 12:55:32

Title: DC++ and spyware
Post by: Requiem on 20 January, 2005, 12:55:32
Is the information on this page (http://snailsoft.cjb.net:20080/Sites/Personal_Pages/sDC/warned.html)  correct? I think the writer is true, because I saw DC++ 0.668 trying to send mails (as reported by ZoneAlarm).. What do you think?
Title: ZoneAlarm
Post by: BoJlk on 20 January, 2005, 13:19:49
ok, then you don't have to worry about anything
your ZoneAlarm will block future attempts of DC to send mail, (click never to aks you again in ZoneAlarm)

There's no "Hacked" Clients, it's an OpenSource anyone can add/Modify the Program.
and the old version of DC (v0.403) was trying to send mail, when i was using it.
Title:
Post by: Requiem on 20 January, 2005, 13:32:33
Quote(click never to aks you again in ZoneAlarm)

 a bit late buddy.. Once I tried to be active on port 25 to pass my universities' firewall, and I thought these alarms meant it is still trying :) I know, I am stupid..

And.. What about connecting to tracking services?
Title:
Post by: blackwings on 20 January, 2005, 14:28:22
QuoteOriginally posted by BoJlk
ok, then you don't have to worry about anything
your ZoneAlarm will block future attempts of DC to send mail, (click never to aks you again in ZoneAlarm)

There's no "Hacked" Clients, it's an OpenSource anyone can add/Modify the Program.
and the old version of DC (v0.403) was trying to send mail, when i was using it.
dc++ 0,668 sends emails? does it send to a certain IP or through a certain port?
Title:
Post by: Requiem on 20 January, 2005, 14:39:25
As written in the linked page:

QuoteM-WEB, proxy, BSA.co.za AP2P" ( 196.2.147.80 ) [protocol: TCP - src: 3076 / dst: 25]

(Attempts to silently email personal information to the BSA Anti Peer to Peer agency, a division of the DCMA and associate to the RIAA.)
Title:
Post by: BoJlk on 20 January, 2005, 14:49:12
QuoteAnd.. What about connecting to tracking services?
Not that i know of...

Quotedc++ 0,668 sends emails? does it send to a certain IP or through a certain port?

Damn, i could have told you but i've erased all my Firewall log  :(
Title:
Post by: (uk-kingdom)John on 20 January, 2005, 16:08:47
this a joke or is it real? and if it's real what made dcdev want to make a client send emails to bsa? can't trust any dc client now, i'll use a different one till someone from dcdev tells us whats going on.
Title:
Post by: Meka][Meka on 20 January, 2005, 16:36:54
*edc user, safe  8)
Title:
Post by: GargoyleMT on 20 January, 2005, 19:36:44
QuoteFrom BoJlk:
ok, then you don't have to worry about anything
your ZoneAlarm will block future attempts of DC to send mail,
But, you're not blocking DC++ from sending mail, you're blocking uploads to a user who has made his DC++ listen on the SMTP port - probably in an effort to avoid packet shaping at his ISP or university.

Good firewall/AV programs could inspect the packet to notice that it's not speaking valid SMTP...

QuoteFrom Meka][Meka:
DCDEV ARE FAGS > GargoyleMT SUCKX DiCK!
Didn't I ban you when you were flooding DCDev Public?  You were attacked, and the attacker claimed that they were us.  You then attacked us.

I swear I spoke to someone higher up on the TE hierarchy and settled this.
Title:
Post by: BoJlk on 20 January, 2005, 20:24:10
Quoteyou're not blocking DC++ from sending mail, you're blocking uploads
When you allow or disallow DC to work with TCP/UDP protocols, not any other...
Mail = SMTP protocol

Quoteblocking uploads
Uploading is outgoing Request...
Sending SMTP (Mail) DC will initiate an outgoing Request to Remote IP Address thru PORT:25.
and that will be Blocked.

ToGargoyleMT:
Meka][Meka has created some Flooding devices  :D
even so he's one hell'of Talented guy!
Title:
Post by: bastya_elvtars on 20 January, 2005, 20:36:59
QuoteOriginally posted by GargoyleMT
QuoteFrom Meka][Meka:
DCDEV ARE FAGS > GargoyleMT SUCKX DiCK!
Didn't I ban you when you were flooding DCDev Public?  You were attacked, and the attacker claimed that they were us.  You then attacked us.

I swear I spoke to someone higher up on the TE hierarchy and settled this.

hmm our fan club has been made public i see. sorry for late reaction, my windows died after 9 months of work ;)
Title:
Post by: GargoyleMT on 20 January, 2005, 21:34:04
QuoteOriginally posted by BoJlk
When you allow or disallow DC to work with TCP/UDP protocols, not any other...
Mail = SMTP protocol
SMTP is IP based protocol.  Feel free to read the latest protocol specification for it (http://www.faqs.org/rfcs/rfc2821.html)

QuoteOriginally posted by BoJlk
Uploading is outgoing Request...
Sending SMTP (Mail) DC will initiate an outgoing Request to Remote IP Address thru PORT:25.
and that will be Blocked.
Agreed, and that scenario is identical whether sending mail or trying to upload a file to a remote user who has set their DC++ to listen to the SMTP port....


QuoteOriginally posted by BoJlk
Meka][Meka has created some Flooding devices  :D
even so he's one hell'of Talented guy!
If he's made flooding programs, then he has programming knowledge.  What does that have to do with what I said?
Title:
Post by: plop on 20 January, 2005, 21:54:13
Quoteountry: SOUTH AFRICA

NOTE: More information appears to be available at AR56-ARIN.


OrgName:    M-WEB
OrgID:      MWEB
Address:    Private Bag X14
Address:    Tygervalley
Address:    Cape Town, South Africa 7536
City:      
StateProv:  
PostalCode:
Country:    ZA

NetRange:   196.2.128.0 - 196.2.159.255
CIDR:       196.2.128.0/19
NetName:    MWEB-2BLK
NetHandle:  NET-196-2-128-0-1
Parent:     NET-196-0-0-0-0
NetType:    Direct Allocation
NameServer: FALCON.MWEB.CO.ZA
NameServer: NS2.MWEB.CO.ZA
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    1998-09-22
Updated:    2000-06-02

TechHandle: AR56-ARIN
TechName:   Retief, Andre
TechPhone:  +27 21 9188300
TechEmail:  *******@mweb.com

OrgAbuseHandle: ABUSE364-ARIN
OrgAbuseName:   Abuse
OrgAbusePhone:  +27 21 596 8300
OrgAbuseEmail:  *****@mweb.com

OrgNOCHandle: NOC1327-ARIN
OrgNOCName:   Noc
OrgNOCPhone:  +27 21 596 8300
OrgNOCEmail:  ********@mweb.com

OrgTechHandle: NOC1327-ARIN
OrgTechName:   Noc
OrgTechPhone:  +27 21 596 8300
OrgTechEmail:  ********@mweb.com

# ARIN WHOIS database, last updated 2005-01-19 19:10
doesn't look like bsa @ all does it??


tcp/udp in noob style.

tcp: i call you on the phone, you answer and say your name, i check this and identify myself.
when all this is correct we start talking.

udp: i start shouting and pray that you hear it.

smtp uses tcp (the phone) 2 connect and then talks the smtp language.
if my dc++ client connects 2 a smtp server and talks dc then the mailserver has no idea what my dc++ client is talking about and disconnects.

btw doesn't the dc++ faq tell you that you shouldn't use zonealarm cause it's dead stupid and can cause your up/downloads 2 become corrupted.?

plop
Title:
Post by: bastya_elvtars on 21 January, 2005, 22:11:51
QuoteOriginally posted by plop
btw doesn't the dc++ faq tell you that you shouldn't use zonealarm cause it's dead stupid and can cause your up/downloads 2 become corrupted.?

plop

if you search my post, i have mentioned this at least 3 times.

btw leave me alone with antip2p i have been cut off from DC for a month thx to them. (So many ppl are happy now  :P )
Title:
Post by: AlwaysConnected on 22 January, 2005, 20:20:34
if it strue ;)

i show my
;)(http://www.fooliospie.com/Beach2003/ass.JPG)

to the  (http://www.bsa.org/i/logo.gif)

good joke ppl
Title:
Post by: Requiem on 22 January, 2005, 21:03:57
I see the page is destroyed so a backup is always fine :) Will try to find a host for it.
Title:
Post by: bastya_elvtars on 23 January, 2005, 00:04:08
hmm AC, mine is a bit more hairy :D

btw i hope they won't eva see my FACE.   :rolleyes:
Title: New host
Post by: Requiem on 05 February, 2005, 19:07:52
New host is http://www.students.itu.edu.tr/~canem/warned.htm (http://www.students.itu.edu.tr/~canem/warned.htm)
Title:
Post by: VidFamne on 07 February, 2005, 01:21:13
.
Title:
Post by: Meka][Meka on 07 February, 2005, 11:16:15
QuoteOriginally posted by AlwaysConnected
if it strue ;)

i show my
;)(http://www.fooliospie.com/Beach2003/ass.JPG)

to the  (http://www.bsa.org/i/logo.gif)

good joke ppl

lol if u look like that n have ass like that then if i tell u im the bsa will u do the same to me?  :D  ;)
Title:
Post by: vick on 21 February, 2005, 23:48:17
QuoteOriginally posted by GargoyleMT


QuoteFrom Meka][Meka:
DCDEV ARE FAGS > GargoyleMT SUCKX DiCK!
Didn't I ban you when you were flooding DCDev Public?  You were attacked, and the attacker claimed that they were us.  You then attacked us.

I swear I spoke to someone higher up on the TE hierarchy and settled this.

hmmmmmm, how high in the hierachy did u go then chum? cos last time i checked MEKA was still boss ;)

o yaeah i second that post up their as i can tell u for a fact as could many here, that he has skilss equal to anyone here and talent and instinct like no other , full stop.