Skip to content
MSN

Detecting Stealthed Scripts with Vincula...

A TG007 community discussion started by »¤§£¥¤«2.

Discussion 7 posts
Page 1 of 1
Open
Topic #1361 · 7 published posts · 691 views
oops.gif Is it possible to detect these connections that include this ability?? This has got to be one of the most annoying things anyone has made public in a long time. We use your scripts to protect our rooms and then a stealthed connection is created so some idiot can download it and use it for purposes other than what it was (hopefully) intended it for. Now with that said can it be detected in any way?? or do we just have to suffer the idiots new found joy huh.gif

Uh, a stealthed connection? No, its called halting your version. Normally you get a sockopen or a socklisten that goes throughout the connection, and you get a version halt by simpling putting halt or return. Do a DTAE check or something.

I have and it flies in under the wire... And I know it is a script and I know its a connection other than Vincula. But thats all I know. If it isnt this ability called Stealth then I apologize but something is running around out there on MSN as I have seen it in action and it doesnt set off script kickers nor my Viper script warning...

sly, for a script detector to work properly u have to :

 

ctcp check Version

ctcp check DTaE

ctcp check Finger

ctcp check IsItVincula

ctcp check Ping

ctcp check Time

 

(for the last 2 ctcp's, the script is what DOESN'T give reply to those)

 

i hope that helps

on me:*:join:#:hop #

not really as I dont do any of my own scripting so I have very little idea as to what you are saying. If you mean it (the script I am concerned about) isnt replying to a ping or time check, I am sure the script I do use (Kenobi) performs all those checks and it works well on everything else I have encountered, especially vincula scripts. This one though can somehow bypass both my Viper and Kenobi. So you can see my concern as I have never once been let down by either...

 

Ill figure it out eventually though...

 

sorry to have bothered you all wink.gif

it is possible for a script to be completely undetectable, by doing everything the same way webchat would do it, but there are other ways to detect scripts, which most script alarms that i'm aware of don't bother doing. so here is what i know about detecting scripts:

 

a user is probably a script if:

-it is a guest and DB211 is not in its gatekeeper address

-it's away message consists of anything other than "Away"

-it can send messages longer than 255 characters (and is not a guest)

-its profile icon doesn't match what is actually stated in its profile

-its nickname is different from the one that appears at the top of its profile

-if any information for the user (except a plain zero) is given after the colon when you enter the command /who <%#room\bname>

 

also, search the room's access list periodically and look for any entries made by people you don't recognize. this is another way to detect a user who is using a script.

 

but keep in mind that even if you do all of these checks, it will still be possible for a script to go undetected. the best way to keep your room safe is to run a fairly decent script detector to begin with, but also to have good room protections running all the time.

bfush.PNG

-its nickname is different from the one that appears at the top of its profile

 

Hint: raw 311

on me:*:join:#:hop #