Links

Download ReconByFire

ReconByFire's Wiki Page


Reconnaissance By Fire

A recuring challenge when monitoring the activity of online criminals congregating in IRC networks is how to stay undetected by other users and still gather intelligence. CTCP responses can be a plethora of information, but at the same time, often is noticed by the subject since most IRC clients report the attempts of such commands. It is trivial for the subjects to notice recurring patterns of probes from certain nicks and take action to prevent them. Being discovered by the subjects can compromise the validity of the research as well as potentially place the investigator in the line of fire should any of them decide to retaliate.

Reconnaissance By Fire is a simple script to do a quick "shotgun blast" of CTCP requests. It is loud, noisy, and readily noticable by a target. However, it is quick, anonymous, and can yield a lot of information. When executed the script connects to a IRC server, either directly or a proxy, joins the channels specified, and runs CTCP comands on all the connected clients. It then displays any and all information sent back.

Since the user information is customizable, and the ability of the client to go through a Privoxy/tor proxy, allows for near complete anonymity by the investigator.