2008-9-17 20:39:59: [Suspect Hello-Tag: XL](ban)- Client 16128100@85.17.184.1 (59.36.229.100) '[VeryCD][CHN]DHJVvtxF' (eMule v0.48a [VeryCD 080902],None/None/None)
这个是Xtreme7.0的DLP日志,我们可以看出,XL伪装成了VeryCD 080902版,而这种伪装得靠Suspect Hello-Tag检出
以下是VC的DLP日志
代码
2008-9-17 20:37:53: [硬性吸血骡](封禁)- 客户端 114.240.130.243 '[CHN][username]' (eMule v0.47c [20071122],None/None/None)
2008-9-17 20:37:58: [硬性吸血骡](封禁)- 客户端 8364794@61.174.18.254 (61.185.26.40) '[VeryCD][CHN]WJu' (eMule v0.48a [080620],None/None/None)
2008-9-17 20:38:00: [硬性吸血骡](封禁)- 客户端 121.230.160.164 '[CHN]OEGEK\L' (eMule v0.48a [20080409],None/None/None)
2008-9-17 20:38:01: [硬性吸血骡](封禁)- 客户端 5085318@221.130.192.27 (118.74.109.210) '[VeryCD][CHN]FP' (eMule v0.48a [V 080828],None/None/None)
2008-9-17 20:38:13: [硬性吸血骡](封禁)- 客户端 4400360@221.130.192.27 (222.240.77.79) '[VeryCD][CHN]R' (eMule v0.48a [V 080828],None/None/None)
2008-9-17 20:38:13: [硬性吸血骡](封禁)- 客户端 124.115.250.232 '[CHN]yourname' (eMule v0.47c [20071122],None/None/None)
2008-9-17 20:38:13: [检测哇嘎嘎](封禁)- 客户端 1@0.0.0.0 (58.213.205.169) '[CHN][VeryCD]yourname' (eMule v0.47c,Connecting/None/None)
2008-9-17 20:38:22: [硬性吸血骡](封禁)- 客户端 221.5.81.47 '[CHN]B' (eMule v0.48a [20080409],None/None/None)
2008-9-17 20:38:23: [硬性吸血骡](封禁)- 客户端 5818546@221.130.192.27 (220.182.3.30) '[CHN][VeryCD][eMule][Flashget]C' (eMule v0.48a [VeryCD 080902],WaitCallbackKad/None/None)
2008-9-17 20:38:23: [硬性吸血骡](封禁)- 客户端 8111246@194.30.160.41 (218.84.18.102) '[VeryCD][CHN]EmLxve' (eMule v0.48a [V 080828],None/None/None)
2008-9-17 20:38:26: [硬性吸血骡](封禁)- 客户端 4716722@61.174.18.254 (58.213.222.134) '[VeryCD][CHN]Jh' (eMule v0.48a [V 080828],None/None/None)
看到Suspect Hello-Tag的检测方式了吗?!
后果我就不说了吧
[0]
[0]
[回复]