Re: Drop Dynamic Querying

Bill Pringlemeir <[email protected]>
Newsgroups gmane.network.gnutella.devel
Message-ID <[email protected]>
> 1a. Re: Drop Dynamic Querying - It only benefits Spammers these days
>     Posted by: "Serguei Osokine" [email protected] osokin_paragraph_com
>     Date: Sat Mar 24, 2007 1:52 pm ((PDT))

> 	So the spam comes in two forms: from their machines and through
> poor souls who were duped into downloading this crap and now are the
> rebroadcasters.

This is a good point.  One small change that might prevent the second case is
that all downloaded files are immediately made available for upload.  This was
done in order to prevent "free loading".  However, downloaded files haven't had
time to be reviewed by the user.  This helps to propogate SPAM.

PeerGaurdian might be great for Windows users.  Most *nix users will have ip
blocking capabilities that can be automated with a script and a list of hostile
peers.  Eg, 

# Loop over hostiles.txt and deny any connections...
echo -n "Hostile"
for i in `grep -v ^# hostiles.txt | sort -n`; do iptables -A INPUT -i $EXTIF -s
$i -d $ANY -j REJECT && echo -n "."; done;
echo "Done"

Some Gnutella clients (like gtk-gnutella) also refuse to connect to hostile
peers at the application level.  The problem with this is that the SPAMers are
not static and this list has to be constantly updated all the time.  One can
also find references to people who have aquired new IP address ranges and been
blacklisted, because the previous owner was a SPAMMER (or they are included in
a bogon list).  This can also happen with P2P spammer lists.

Credence addresses both cases, but requires that users vote wisely (and often);
DQ should be altered to exclude low correlated nodes from searches.  GUESS
shifts searching from the network to the node, so it *seems* more difficult for
SPAMers to monopolize queries with their responses.  GUESS can also exclude any
nodes with SPAM responses from future searches.  Spam responses can be found
via credence type voting or by static hash lists and/or response text [ie,
*Im_a_spammers*.mp3].  Unfortunately, DQ can only exclude a top-level ultra
which may prevent all connected nodes from being queried.  I don't think there
is an easy (secure) way to propogate this information towards the direct
connections to the spam source.  Maybe queries could have a "deny list"
attached (or some way to obtain).  Ie, don't forward my query to these nodes.

fwiw,
Bill Pringlemeir.



 
____________________________________________________________________________________
TV dinner still cooling? 
Check out "Tonight's Picks" on Yahoo! TV.
http://tv.yahoo.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.