Well, you said he uses tintin, tintin usually means a UNIX os, so... when your mud detects him doing this to you, have you mud port scan him and start DoS'ing him... this is probably a bad idea, very illegal, but hey, it'd tick him off, might make him go away..
(Seriously here...) It might also be more effecient when determing if it's this guy, to hash all the connect hosts (the corresponding value would be number of connections), this will save searching through your descriptor list anyway. But Yui has probably got it right, get the mud to auto-add him to a firewall if you can.
|