DNSBLs and IRC
Andy Smith <[email protected]>
| Newsgroups | gmane.network.irc.blitzed.general |
|---|---|
| Message-ID | <[email protected]> |
A log of a discussion that took place between several members of the
irc-security list. I was not present.
Session Start: Tue May 25 18:22:39 2004
Session Ident: #irc-security
[06:22:39] * Now talking in #irc-security
[06:22:39] * Topic is 'uninstyler version 0.0.2 | porno.exe version 7 ($fd_offset = 0x28be5) | "Modern cyberspace is a deadly festering swamp, teeming with dangerous programs such as ''viruses,'' ''worms,'' ''Trojan horses'' and ''licensed Microsoft software'' that can take over your computer and render it useless." -- Dave Barry'
[06:22:39] * Set by PinkFreud on Sun Jan 18 19:17:04
...
[07:19:17] * magick has joined #irc-security
[07:19:29] <reed> hiya :)
[07:19:33] <magick> ello
[07:20:19] <magick> so... any brainstorming on blacklisting?
[07:20:21] <reed> yap
[07:20:28] <reed> I combined the ideas :p
[07:20:35] <reed> take the non-related "karma" system
[07:20:52] <reed> have a blacklist where it keeps track of how many people report that ip/host
[07:20:57] <reed> i.e., points
[07:20:58] * peter has joined #irc-security
[07:21:02] <magick> that makes sense
[07:21:06] * peter is now known as Peter
[07:21:10] <Peter> evening
[07:21:11] <reed> people can chose how many networks must have reported the ip/host
[07:21:20] <reed> before it uses it on their network
[07:21:24] <reed> plus categories for stuff
[07:21:34] <magick> can that value be conveyed by the (variable) return code?
[07:21:47] <reed> yes
[07:22:05] <reed> each network will have a login for the bl
[07:22:10] <reed> to keep up with stuff
[07:22:16] <magick> rsync?
[07:22:26] <reed> can be, or some other way
[07:22:28] <magick> + rbldnsd?
[07:22:30] <magick> or similar
[07:22:37] <mst-_> reed: therein lays the problem. You can have per-host dnsbl, but not per-user one. There's too much various metadata, need of authentication and so on. In essence, karma is only valid in the network's namespace, unless we want to repeat the ms passport experiment
[07:22:52] <mst-_> magick: thats how all blacklists update the mirrors
[07:22:58] <mst-_> rsyncing zone files around
[07:23:01] <reed> ye
[07:23:03] <reed> yes
[07:23:06] <magick> what I would like to see is a SpamAssassin style approach to the existing DNS blacklists
[07:23:15] <magick> i.e., I trust DSBL far less than BOPM
[07:23:28] <magick> and ideally, reaction should reflect that
[07:23:29] <Peter> Wouldnt it make sense to have karma for the networks? Eg. If they have good karma their blacklisted host means more to othe networks, and if they have bad karma.. well it doesnt, but the total amount of karma on a host signifies wether it'll be blacklisted or not?
[07:23:37] <reed> true
[07:23:49] <reed> that's why I called for collaboration
[07:23:49] <reed> :p
[07:23:54] * blackice has joined #irc-security
[07:23:55] <reed> see, this works better? :P
[07:24:26] <Peter> eg. network #1 has 0.5 karma, and network #2 has 0.5 karma, and they both blacklsit the host. giving it 1.0 karma which the netowrk running the blacklist on could determine what level of karma a host needs to be blocked on the network?
[07:24:40] <Peter> kinda like how SA works with 'points'
[07:25:01] <magick> that works
[07:25:20] <mst-_> Peter: the point of karma is permanent accumulation
[07:25:24] <Peter> because, as you know. this *IS* irc.
[07:25:34] <Peter> And, not all networks that participate in this RBL make be exactly honest.
[07:25:35] <mst-_> think "slashdot karma"
[07:25:37] <Peter> (If it happens).
[07:25:40] <Peter> Yeah, thats what I was thinking.
[07:25:41] <mst-_> spamassassin is score
[07:25:49] <Peter> But I mean, each HOST. If more then one network blacklists it..
[07:26:18] * Peter doesnt exactly know how spam blacklists work..
[07:26:42] <magick> the more awkward question is
[07:26:51] <magick> how do we define what to blacklist
[07:26:52] <mst-_> Peter: blacklist is a central authority, usually one person, who operates spamtraps and adds received spam sources to the blacklist.
[07:27:02] <Peter> That wouldnt work with IRC.
[07:27:06] <magick> what is a global threat (e.g. Fyle bots); what is local
[07:27:06] <reed> well, we have to change that
[07:27:09] <Peter> "central" wouldnt work.
[07:27:15] <Peter> Needs to be somehow karma based.
[07:27:25] <mst-_> Peter: there are multiple blacklists, each with its own inclusion policy
[07:27:36] <Peter> mm
[07:28:13] <mst-_> you can have one trojaned machines list, one open proxies list, one known script kiddies list, and you can combine them on network (or even channel) basis to achieve desired results.
[07:28:46] <magick> ok, we define trojaned as "identified trojan" or "if it walks like a duck, and it quacks like a duck..."
[07:28:49] <magick> ?
[07:28:57] <mst-_> To think of it, an irc network could probably set a global limit and accumulate all the warnings from blacklists that go below the threshold in a per-user variable.
[07:29:17] <mst-_> magick: if it spams, floods, relays nickname lists, it's a trojaned box.
[07:29:53] <magick> that works... are we hoping to store evidence to support listings, or just remove on admin request or what?
[07:30:09] <magick> I'm thinking of one huge channel we have which falls foul of every DNSBL I know
[07:30:17] <magick> it's full of argentinian cybercafe users
[07:30:19] <Peter> thats where it gets tricky.
[07:30:20] <Peter> lol!
[07:30:28] <Peter> Yes, that'd be very handy.
[07:30:28] <mst-_> magick: the standard practice of blacklists is to keep evidence files open.
[07:30:29] <magick> one infection, bang goes 20 people
[07:30:54] <Peter> The problem is, how do we _verify_ that the ban is accurate? What happens if we have a submitter that isnt exactly "level"
[07:31:13] <blackice> i dont think there's a way to be certain about any submitter
[07:31:23] <reed> that's why you need to have a login
[07:31:24] <reed> to submit
[07:31:30] <reed> not just anybody can submit
[07:31:37] <magick> we can however record how many of a network's submissions are challenged
[07:31:43] <mst-_> Peter: there's no way, and it's not needed all that much. Besides, the number of submitters must be limited to trusted, qualified people.
[07:31:43] <Peter> Hm, and say.. if more then one person submits it, the points on the host goes up.
[07:31:49] <magick> and deal with that which is statistically suspicious
[07:31:56] <reed> Peter: yap
[07:32:10] <reed> most spammers just change networks and such
[07:32:16] <reed> so it would work
[07:32:16] <Peter> And networks can define if they're using our blacklsit, what threshold they start banning at.
[07:32:26] <reed> Peter: yes, that's what I said :)
[07:32:37] <magick> we would have to be able to give realistic guidance, though
[07:32:44] <mst-_> Well.. I'm a radical. If the IP's unclean, gline it.
[07:32:56] <mst-_> BTW, dont forget that the listings have time to live records.
[07:32:58] <magick> we can't just add one point per report, or the values will change as it grows
[07:33:23] <magick> so, what is the reasonable threshold of reports
[07:33:24] <BarkerJr> it isn't 9pm yet, go away everyone :P
[07:33:25] <mst-_> magick: statistically speaking, linear scores arent the best solutions when you have different levels of trust.
[07:33:35] <reed> BarkerJr: I said they could start coming now :p
[07:34:05] <mst-_> magick: who are the people who'll be submitting? For instance, my current antispam bot has 100% accuracy, no false positives.
[07:34:14] <BarkerJr> ah, well, I still have 20mins more of the screensavers, so come back later :P
[07:34:15] <mst-_> I extracted the list of nicks from the trojan myself.
[07:34:36] <magick> I can still find you a moron who will give you a false positive :P
[07:34:48] <magick> make it idiot proof someone will make a better idiot
[07:34:54] <blackice> heh
[07:35:05] <magick> what sanity checking can we do against plain malicious submissions?
[07:35:12] <Peter> karma
[07:35:12] <mst-_> magick: if someone is actually stupid enough to mimick a spambot...
[07:35:15] <Peter> for each submitter
[07:35:23] <magick> oh, they are
[07:35:26] <magick> they are
[07:35:49] <mst-_> magick: there are two real options. Either controlled number of submitters, or web of trust with root in the very same limited number of submitter and exponential growth of trust.
[07:36:02] <Peter> magick: only, uhm.. people from .br/.ar, and do must of us want them on our networks?
[07:36:15] <magick> lol send em to us :)
[07:36:17] <Peter> s/must/most/g
[07:36:33] * Peter has *.br and *.ar akilled on his network =)
[07:36:44] <blackice> i've been tempted
[07:36:45] <magick> the problem is, if it's too controlled how does it become widely effective...
[07:37:03] <Peter> magick: we get big networks to support this.
[07:37:22] <mst-_> magick: perfectly. Look at SPEWS. They don't accept submissions at ALL.
[07:38:24] <magick> and how does that translate to IRC? something has to detect and report the connect in the first place
[07:39:53] <magick> sine qua non
[07:40:28] <mst-_> uhm
[07:40:41] <mst-_> you're magick
[07:40:43] <mst-_> you're part of the system
[07:40:48] <mst-_> you see a spamming bot, you report it
[07:41:02] <magick> you plan on manual submissions?
[07:41:14] <Peter> WHat would the TTL be?
[07:41:15] <magick> you gotta be joking... we got an akill list of 8,000
[07:41:18] <mst-_> someone else does, goes to you, you check and report it.
[07:41:18] <mst-_> I am a part of the system
[07:41:19] <Peter> I have a *really* bad habit if I have a spam bot or whatnot, or a drone/proxy that it ends up on perm. akill
[07:41:21] <mst-_> I have a bot that is configured to detect specific kind of trojan with 0% false positives. It can report automatically.
[07:41:31] <mst-_> Peter: case to case.
[07:41:31] <magick> we set ours short, longer for repeats
[07:42:12] <mst-_> magick: manual submission always complements spam traps. If the target network refuses to comply, you will have to extend the coverage anyway.
[07:42:18] <Peter> My akill list was over 7,000 akills.. and im a pretty small network.
[07:42:49] <magick> manual submission is a useful extra
[07:43:05] <magick> but, detection of anything which comes in high volumes needs automated
[07:43:22] <mst-_> magick: you do realise of course that neither is a problem, right?
[07:43:44] <magick> well... automation is a problem, because it means one size fits all software
[07:44:05] <magick> but, it's also pretty much inevitable
[07:44:11] <mst-_> what does it matter? write an XML RPC interface for nominations, and export zone files to blacklists.
[07:44:15] <mst-_> problem solved.
[07:44:26] <Peter> Who runs the central DB?
[07:44:58] <reed> irc-unity
[07:45:04] <blackice> if this gets up and going, i can probably provide a slave nameserver if wanted
[07:45:09] <mst-_> Whoever sponsors the hardware and runs the list.
[07:45:34] <reed> I would say we use the irc-unity.org domain
[07:45:40] <mst-_> Peter: it doesnt matter as long as everyone agrees on the purpose and the policy of the list.
[07:45:42] <blackice> sounds good to me
[07:45:54] <mst-_> reed: don't make this mistake.
[07:46:02] <mst-_> A blacklist like this is an instant DDoS target
[07:46:10] <reed> true
[07:46:15] <blackice> good point
[07:46:19] <mst-_> You'd want to keep authorative nameservers as far as possible from your networks.
[07:46:37] <mst-_> Preferrably, in someone else's hands, redundant, and anonymous.
[07:46:48] * jd has joined #irc-security
[07:46:52] <magick> hmmmm
[07:46:54] <@PinkFreud> sweet jeebus, that's a lot of posts.
[07:46:55] <jd> evening
[07:46:58] * jd is now known as scaryrobot
[07:47:01] <Peter> evening
[07:47:02] <reed> hey PinkFreud
[07:47:03] <reed> wb
[07:47:06] <@PinkFreud> sweet jeebus, this is a lot of people, too.
[07:47:07] <scaryrobot> did i miss much?
[07:47:12] * @PinkFreud blinks
[07:47:16] <reed> PinkFreud: I invited the list here
[07:47:20] <Peter> mst: What kind of bandwidth are we looking at?
[07:47:20] <reed> hope that's ok :p
[07:47:23] <@PinkFreud> ahhh :)
[07:47:29] <magick> one way to get users :)
[07:47:30] <@PinkFreud> that explains that :)
[07:48:15] <Peter> We could have a type of BT-like structure for distribution, or similiar
[07:48:29] <mst-_> Peter: no idea whatsoever, but even on primary nameservers, it'd be low.
[07:48:38] <mst-_> Peter: DNS is a huge distributed cache.
[07:48:42] <Peter> mst: define "low".
[07:48:42] <scaryrobot> would someone mind filling me in?
[07:49:00] <Peter> i mean, I can stick a connection out there thats used for nothing else.
[07:49:16] <mst-_> Peter: you would want to talk to AHBL folks and divide that perhaps by 10
[07:49:26] <@PinkFreud> i'll be back in an hour or so.
[07:49:32] * Peter was thinking a T1 or something
[07:49:36] <reed> PinkFreud: any of the other ops around to keep watch?
[07:49:46] <reed> in case some lamers on the list try to cause trouble?
[07:49:56] <@PinkFreud> no idea.
[07:49:59] <reed> k
[07:50:03] <@PinkFreud> i suspect it'll be ok. heh.
[07:50:11] <mst-_> PinkFreud: first bot to directly advertise www.ownclub.net today
[07:50:11] <BarkerJr> hi, I'm back :)
[07:50:23] <reed> I'll go bug your help chans if somebody does
[07:50:26] <@PinkFreud> mst-_: nice
[07:50:30] <@PinkFreud> reed: nod
[07:50:34] <@PinkFreud> ok, bbl ;)
[07:50:44] <reed> PinkFreud: not going to stay for the talks? :P
[07:51:03] <mst-_> Peter: I seriously have no idea
[07:51:27] <reed> scaryrobot: we're discussing IRC DNSBLs
[07:51:38] <scaryrobot> yep, just wondered if you'd started already
[07:51:43] <@PinkFreud> can't at the moment
[07:51:45] <reed> and how to effectively and efficiently use it
[07:51:54] <@PinkFreud> give me about an hour, though... :)
[07:51:57] <reed> lol
[07:51:57] <reed> k
[07:52:04] <reed> we'll probably still be at it
[07:52:19] <reed> people need to check their mail
[07:52:21] <reed> and join
[07:52:21] <reed> lol
[07:53:35] <mst-_> reed: managing dnsbl is simple, and setting it up is even simpler.
[07:53:53] <mst-_> The only more or less annoying part would be actually modifyinh ircds
[07:54:06] * Byte has joined #irc-security
[07:54:08] <mst-_> making a large network adapt it as a network wide update is the toughest.
[07:54:21] <scaryrobot> would a gatekeeper bot not be easier to implement?
[07:54:25] <magick> no need to - it can be consulted by bopm; service bots can handle detection
[07:54:31] * TRoN has joined #irc-security
[07:54:37] <blackice> not all nets run bopm though
[07:54:52] <magick> well, they can if they want to use DNSBLs and don't have proprietary software
[07:55:13] <TRoN> greetings...
[07:55:21] <scaryrobot> greetings
[07:55:23] <mst-_> I heard bopm is quite a resource hog
[07:55:29] <blackice> it can be
[07:55:34] * mst-_ doesnt run his own servers so I wouldn't know.
[07:55:38] <magick> works fine for us, not that we have the highest ever connect rate
[07:55:53] <magick> and I use about 5 blacklists with it
[07:55:55] <magick> copes
[07:56:20] <scaryrobot> i'll brb
[07:56:20] * scaryrobot Quit (Quit)
[07:56:24] <BarkerJr> testing every IP that gets mailed to you can take some bandwidth
[07:56:32] <magick> darn right it can
[07:56:42] <mst-_> blackice: as I said, one could probably write a DNS proxy hack that returns predefined tokens instead of reverse resolution if the IP is blacklisted, and the server could simply be configured
[07:56:42] <mst-_> ...to ban those specific tokens as @hosts
[07:56:47] * scaryrobot has joined #irc-security
[07:57:06] <reed> wb scaryrobot
[07:57:08] <scaryrobot> ty
[07:57:14] <Peter> blackice: I dont run BOPM.
[07:57:27] <mst-_> blackice: it doesnt work that way.
[07:57:30] * Peter refuses to run bopm.
[07:57:44] <Peter> mst-_: well, im willing to give a dedicated connection/box to it.
[07:57:51] <Peter> if it gets off the ground, that is.
[07:57:54] <mst-_> blackice: if you run a local forwarding cache, you will practically save on 90% of connects
[07:57:56] <magick> my point is not that the world should run bopm, BUT that those who just need to consult our proposed blacklist can do so
[07:58:15] <reed> other irc programs can use dnsbls
[07:58:16] <reed> lol
[07:58:23] <mst-_> magick: a formal statement of intent and basic principles must be drawn
[07:59:05] <mst-_> magick: perhaps, but I am not certain if we should even bother ourselves with open proxies right now,. they're way less bothersome than say spybots
[07:59:16] <magick> I guess that starts with defining what we need to block
[07:59:26] <reed> well, we want categories
[07:59:31] <magick> well, we don't concern ourselves with proxies - blitzed does that :)
[07:59:32] <reed> different networks want to block different things
[07:59:34] <blackice> there's other dnsbls that deal with open proxies already anyway
[07:59:47] <magick> what sort of bots will we block, on what evidence
[08:00:10] <magick> offer the option to block, even
[08:00:48] <mst-_> magick: we dont need a strict procedure of evidence evaluation if the staff that's allowed to submit is composed from limited number of qualified people.
[08:01:05] <mst-_> Otherwise, I guess manual verification, redundancy, and personal trust from person to person
[08:02:03] <magick> that works beautifully on a small scale
[08:02:13] <reed> shall we have one login per network?
[08:02:24] * Homer has joined #irc-security
[08:02:27] <reed> or what
[08:02:38] <Peter> What requirements for the network being accepted?
[08:02:40] * flurdoing has joined #IRC-Security
[08:02:44] <Peter> Being around for a year or more?
[08:02:46] <Homer> lo
[08:02:48] <flurdoing> hello
[08:02:50] <reed> hi :)
[08:02:53] <Peter> hi
[08:03:01] <reed> hmm
[08:03:12] <reed> I think age is the best factor to use
[08:03:19] <reed> as users can vary
[08:03:29] <reed> but a year is a while
[08:03:44] <reed> 6 months?
[08:03:45] <Peter> hm, I think a year is what it takes for a network to 'mature'
[08:04:17] <reed> and how will we be able to prove?
[08:04:23] <reed> that the network is at least a year old
[08:04:35] <magick> irc.netsplit.de (or similar)
[08:04:46] <magick> that's pretty comprehensive
[08:04:51] <magick> and there is another such
[08:05:00] <mst-_> being accepted to what? to submissions?
[08:05:06] <mst-_> they are on person basis
[08:05:13] <mst-_> by god, dont involve network officials
[08:05:19] <magick> good point
[08:05:24] <reed> hmm
[08:05:24] <mst-_> you SERIOUSLY dont wnat to mess with undernet "committees"
[08:05:27] <reed> haha
[08:05:28] <magick> we don't need red tape
[08:05:31] <reed> very true :)
[08:05:36] <flurdoing> i think this is undernets biggest flaw
[08:05:54] <mst-_> Being too frigging liberal is Undernet's biggest flaw
[08:05:54] <flurdoing> the best way to combat this nonsense is with a dedicated team with delegated responsibility and authority
[08:06:33] <flurdoing> we need to be able to, say, cancel X undernames and G-Line large numbers of hosts asap when it comes to some rapidly mobile malware
[08:06:58] <mst-_> flurdoing: joint teams = politics = pulling the sheet on your lobbydoer's side = nothing good..
[08:07:02] <magick> which requires a hell of a lot of trust
[08:07:10] <flurdoing> mst-_: we need to start politicking
[08:07:12] <Peter> reed: domain records
[08:07:18] <flurdoing> if the system wont accomodate for this, we need to see to it that it does
[08:07:39] <flurdoing> if you actually care about the survival of undernet that is.. its like saying, there is no point voting because the democrats will win.. we gotta start somewhere.. or so is my belief
[08:07:45] <mst-_> magick: the mere fact that there are people in this room suggests that someone out there has clue
[08:08:00] <flurdoing> blacklisting DNS isnt a solution... lots of the drones are on dynamic ips
[08:08:04] <reed> Peter: yes?
[08:08:12] <mst-_> flurdoing: blacklisting is not just a process
[08:08:14] <Peter> Verify the age of the ntework via whois records.
[08:08:17] <reed> ah
[08:08:19] <reed> true
[08:08:30] <mst-_> the point of blacklisting is not to protect the network
[08:08:38] <TRoN> how about majority rule on submissions... say it takes a few submissions from a few networks to get said host listed
[08:08:47] <mst-_> it is to make the customers of the hostile network complain to their provider.
[08:08:51] <flurdoing> then what? to generate discontent between users and their ISPs?
[08:08:53] <reed> TRoN: that's already been suggested
[08:09:04] <flurdoing> i dont think thats a good solution.. instead of burdening your clients why not burden the irc administration
[08:09:15] <flurdoing> its not fair to burden the chatters, they'll simply go elsewhere
[08:09:23] <mst-_> when the ISP doesnt respond, you escalated their listing.
[08:09:33] <flurdoing> besides, the monolothic ircd is on its way out-- nowadays its all about small private servers
[08:10:05] <mst-_> flurdoing: you'd be surprised. When bezeqint.net was banned on DALnet two years ago or so, the backlash was so overwhelming the VIPs asked the NOC people to negotiate with dalnet kline
[08:10:08] <BarkerJr> fbi and riaa know too much about large networks :)
[08:10:31] <flurdoing> BarkerJr: i believe we're discussing security, not privacy ;)
[08:10:34] <mst-_> flurdoing: for warez and floodnets, sure. But large networks dont go anywhere.
[08:10:37] <flurdoing> if i may so comment =)
[08:10:42] <BarkerJr> hehe ok
[08:11:20] <mst-_> By the way, anyone logs this?
[08:11:26] <reed> yes
[08:11:30] <mst-_> there are some people on undernet whod love to read it later on
[08:11:35] <flurdoing> yeah, i'll log
[08:11:42] <reed> I'm logging in
[08:11:42] <reed> :)
[08:11:44] <reed> it
[08:11:44] <blackice> i autolog everything
[08:11:48] <BarkerJr> I log to a ramdisk :)
[08:11:51] <mst-_> I never log.
[08:11:58] <mst-_> anyhow, back to the point
[08:11:59] <flurdoing> forget logs lets talk about irc security
[08:12:09] * mst-_ lights up a cig
[08:12:21] <mst-_> Peter said he could donate a box
[08:12:24] * Byte complains that it's 2am and goes to bed instead
[08:12:34] <mst-_> who here has experience running production DNS?
[08:12:48] <blackice> i've been running my own dns server for a few years
[08:13:05] <mst-_> blackice: so we can count on you for technical advice.
[08:13:11] <blackice> i can try
[08:13:13] <mst-_> I run my own too, but I am not an expert.
[08:13:17] <blackice> i've only ever used bind though
[08:13:26] <blackice> dont know much about the others
[08:13:27] <reed> tinydns is pretty good though
[08:13:33] <reed> we can always ask on list
[08:13:34] <flurdoing> sorry to bother, but what exactly is the idea with dns?
[08:13:38] <mst-_> yup, tinydns is the thin for this bidznits.
[08:13:46] <mst-_> flurdoing: I'll explain
[08:13:47] <flurdoing> u want to run a dedicated dns server for all irc networks to use or something?
[08:14:10] <mst-_> flurdoing: DNS architecture is by nature distributed cache
[08:14:24] <mst-_> it's excellent for wide broadcast of simple answers to simple requests
[08:14:56] <mst-_> if you want a centralized blacklist of hosts, DNS is the most suitable technology today
[08:15:11] <blackice> rbldns is made for this specifically
[08:15:16] <blackice> never looked at it though
[08:15:17] <flurdoing> so basically a custom dns server which one would query to determine whether a host is blacklisted or not/
[08:15:26] <blackice> yeah
[08:15:31] <mst-_> flurdoing: yes, something very simple technically
[08:15:34] <flurdoing> lol
[08:15:42] <flurdoing> its a nice idea
[08:15:51] <flurdoing> the first thing that comes to mind: overhead, overhead, overhead
[08:15:59] <mst-_> there won't be overhead.
[08:16:04] <flurdoing> an extra query per connection for one
[08:16:23] <mst-_> when you query www.google.com you don't query the root nameservers and then google's authority nameservers every time
[08:16:34] <mst-_> Your ISP has a cache which remembers results.
[08:16:41] <flurdoing> thats because my dns server wll synch with my ISP and cache results
[08:16:50] <flurdoing> that wont be the case with your dns server
[08:16:53] <mst-_> you run such a cache directly in front of your ircd.
[08:16:57] <mst-_> flurdoing: no, wrong.
[08:17:09] <flurdoing> you'll still have to query your own cache
[08:17:10] <mst-_> DNS cache is not the same as DNS server
[08:17:30] <mst-_> yup, but what do you care? locally it's ten times faster and you dont wste the bandwidth
[08:17:40] <flurdoing> oh right, so then the entire blacklisted database will be pushed to the respective cache servers?
[08:17:46] <mst-_> its not pushed
[08:17:54] <mst-_> it's absorbed by caches as it goes.
[08:18:07] <flurdoing> right, so for every unique IP a connection to your dns will be made
[08:18:07] <mst-_> first request you - cache - root server - authority
[08:18:12] <mst-_> second request you - cache
[08:18:17] <flurdoing> but for all cached hosts it'll be local
[08:18:20] <mst-_> correct
[08:18:31] <flurdoing> there is still significant overhead imo...
[08:18:41] <reed> would say different TTLs for repeat offenders
[08:18:45] <reed> i.e.
[08:18:46] <flurdoing> why not just distribute ban lists of hosts u dont want connecting?
[08:18:48] <reed> higher TTLs
[08:18:58] <mst-_> if you are undernet, 100,000 users and of them 2,000 abusive hosts, and every cached record is 512 bytes of RAM, it's just a megabyte of memory
[08:19:02] <mst-_> piece of cake
[08:19:07] <flurdoing> if i'm not mistaken you intend on setting relatively wide bans prohibiting entire networks as a solution to dynamically assigned hosts
[08:19:32] <flurdoing> thus the entire blacklist database [if i may so call it] should be relatively small (a few 100 kbs?)
[08:19:41] <mst-_> flurdoing: dont forget. If the abusive networks refuse to cooperate, you extend thwe coverage against them. That is the point of blacklists.
[08:19:46] <blackice> i thinkk if there was enough abuse from certain networks, it would be justified
[08:19:56] <mst-_> blackice: ttnet.net.tr
[08:20:01] <mst-_> onvol.net
[08:20:08] <blackice> i'm really close to banning *.tr
[08:20:17] <blackice> never see anything but crap from there
[08:20:26] <flurdoing> mst-_: i see.. also, out of curiosity for myself and for all the log readers... what exactly do u deem to be appropriate action for an ISP to take upon being advised on an epistemic drone problem?
[08:20:44] <mst-_> flurdoing: immediate suspension of service without prior notice.
[08:20:49] <BarkerJr> klavyes, blackice
[08:20:50] <blackice> cut the customers connection until they clean up their machine
[08:21:20] <flurdoing> hrm...
[08:21:40] <mst-_> flurdoing: THE best way to draw someone's attention
[08:22:02] <mst-_> What? The old lady doesnt know how to clean up her computer? We're so sorry, per-router firewall service for $9.95/month
[08:22:26] <mst-_> My ISP does it. I dont see why everyone else shouldn't.
[08:22:44] <flurdoing> i'm playing devils advocate by arguing here, but i hope you realize that this is illegal
[08:22:44] <flurdoing> i dont think that'll fly unfortunately
[08:22:44] <flurdoing> if my ISP disconnected me without prior notice i would never sign up with them again, ISPs know that
[08:22:58] <blackice> it's not illegal if it's in the AUP
[08:22:59] <mst-_> it is not "illegal"
[08:23:18] <flurdoing> disconnection without notice is rarely in ISP TOS
[08:23:27] <blackice> you'd be surprised
[08:23:29] <mst-_> I'm afraid you're wrong.
[08:23:32] <BarkerJr> the aup may be unconstitutional and fightable by law
[08:23:35] <blackice> most have it, few enforce it
[08:23:39] <mst-_> blackice: bollocks
[08:23:43] <mst-_> er, BarkerJr
[08:23:57] <mst-_> Constitution does not oblige commercial entities.
[08:24:01] <flurdoing> its not in my ISP's TOS and as a lawyer-in-training i can tell ya that disconnection without notice is a violation of customer-contract stating that i pay X $ for x days of service =)
[08:24:10] <flurdoing> technically i can sue them for disconnecting me, but thats just my ISP =)
[08:24:21] <mst-_> flurdoing: unless there's an exclusion cause, which is fine by contract law.
[08:24:30] <mst-_> s/cause/clause/
[08:24:53] <mst-_> there is one in my contract
[08:25:08] <flurdoing> not only do i think it is unfair to ask ISPs to take such action, I also think it is unfair to shift the cost of this solution from the IRC server administration to the IRC clients
[08:25:10] <blackice> simple solution, isp doesn't disconnect customer, isp stays blocked until they do
[08:25:12] <BarkerJr> if you park your car in a guarded parking lot ("we're not responsible for your car"), you can still sue them if your car is stolen when the guard is on duty
[08:25:28] <BarkerJr> contracts and aup's are not rock solid
[08:25:29] <mst-_> flurdoing: excuse me. Who is responsible for these costs?
[08:25:56] <mst-_> blackice: and you will be immediately countersued for the same sum.
[08:25:57] <flurdoing> the costs of which i speak are incurred upon irc users within blacklisted networks which are not infected
[08:26:00] <mst-_> err, BarkerJr
[08:26:22] <mst-_> flurdoing: yup. That's reality. Stop seeing ISPs as networks. See them as neighbourhood.
[08:26:39] <flurdoing> blocking access to places by neighborhood is discrimination =)
[08:26:50] <blackice> my server, my property
[08:27:02] <mst-_> flurdoing: so will you sue a pizza place if they refuse to deliver to Harlem?
[08:27:03] <blackice> i have a right to put up a no trespassing sign to whoever i feel like
[08:27:15] <magick> aye, no objections there :)
[08:27:31] * magick lagged... n/m that was to an earlier comment
[08:27:36] <flurdoing> mst-_: fair analogy, but the difference here is that we're talking about the monolithic ircd and not dominos pizza
[08:27:40] <blackice> this is not much different than the current problem with email
[08:27:44] <magick> brain lag as opposed to irc lag
[08:28:09] <flurdoing> you'll be offending all these innocent users because the ircd admins cant get their act together to combat the problem effectively
[08:28:16] <flurdoing> how about a bug ticketing system on undernet for example
[08:28:17] <mst-_> flurdoing: whats the difference? IRC is a public service. If I run my own IRC network, I can put a motd saying "no dogs and niggers allowed", and no one is entitled under any law to sue.
[08:28:20] <flurdoing> report drones and malware
[08:28:27] <reed> this is -not- undernet
[08:28:28] <flurdoing> and a network of analysts and opers that actually WORK TOGETHER
[08:28:29] <mst-_> Access to IRC is not a protected right.
[08:28:31] <Peter> mst: I run production DNS, too.
[08:28:37] <flurdoing> i'm talking EXCLUSIVELY about undernet here
[08:28:38] <Peter> Access to the internet is not a protected right.
[08:28:44] <reed> and plus, I've dealt with undernet for a long time
[08:28:48] <reed> I used to be with abuse-exploits
[08:28:52] <mst-_> flurdoing: it will go greatly on any network where admins trust each other.
[08:28:54] <reed> the group that dealt with drones and such
[08:28:56] <mst-_> Undernet is not one of them.
[08:29:09] <flurdoing> mst-_: thats true, but we can see that as a problem and we can see a simple solution
[08:29:28] <flurdoing> the US government is set up in a similar fashion
[08:29:33] <flurdoing> 'checks and blances'
[08:29:37] <flurdoing> balances^ :)
[08:30:20] <reed> ok
[08:30:27] <mst-_> flurdoing: I want to see you coming to the server admin guy who was billed $30,000 for DDoS bandwidth last year and says that in his face.
[08:30:53] <mst-_> I talked to some smart people on Undernet today
[08:31:06] <mst-_> Undernet aint gonna lift a finger until there's working project.
[08:31:10] <flurdoing> uh thats pretty weak.. if i got billed that amount for running an undernet server i'd pull the plug
[08:31:21] <flurdoing> mst-_: i'd even argue that undernet will never lift a finger
[08:31:31] <Peter> well, we can see if we can get DALnet to cooperate.
[08:31:53] <Peter> Not that dalnet is that large anymore, their abuse team is certianly better then many networks out there.
[08:31:53] <reed> networks will join in if they see it works for other networks
[08:31:56] <flurdoing> but the point i'd like to make is that a solution exists and can be brought about by cooperation and intelligent systems as opposed to wide bans
[08:32:21] <flurdoing> my point is that we cannot shift the cost of politicking amongst ourselves to the clients and their ISPs. it is *Our* problem because these are *our* servers
[08:32:34] <BarkerJr> if you get billed $30,000, you can sue the ddos'er
[08:32:44] <flurdoing> BarkerJr: hehe not if he's in romania or china
[08:32:46] <Peter> I think we should be able to do large blocks if the ISP is unwilling to cooperate with us.
[08:32:51] <mst-_> BarkerJr: that's presuming you have the resources to go after him in discovery
[08:33:06] <Peter> Many IRC networks blocking an ISP is going to get through, however one network blocking it is not.
[08:33:11] <mst-_> flurdoing: the problem is lack of education and fatal flaws in windows.
[08:33:13] <Peter> Unless its a very large network.
[08:33:15] <mst-_> We cant don anything about that.
[08:33:23] <Peter> mst: Other OSes have fatal flaws.
[08:33:29] <flurdoing> Peter: i think you'll never get that to fly on Undernet-- all Undernet has going for it today is its sheer size. if they start limiting clients, undernet will die so fast it'll make all our heads' spin.. dont need to be an oper to know that =)
[08:33:32] <BarkerJr> you can get the fbi to do it
[08:33:42] <mst-_> Peter: the last scandalous worm for *nix was also the first scandalous worm for *nix
[08:33:48] <flurdoing> mst-_: yea perhaps it is.. although i've dealt with several insanely complicated linux based malware
[08:34:00] <mst-_> like Oracle? :P
[08:34:01] <flurdoing> in the mid 90s those freakin zombies drove me up the wall
[08:34:08] <flurdoing> well yeah, there is plenty of vulnerable software
[08:34:09] * Peter hasnt run Linux for years..
[08:34:16] <Peter> wasnt exactly refering to Linux =)
[08:34:33] <flurdoing> meh, whattever-- all POSIX is generally alike =)
[08:34:39] <Peter> Many Oses have problems. But saying Windows is the only one.
[08:34:52] <flurdoing> the main problem is people
[08:34:55] <flurdoing> they dont update
[08:35:10] <flurdoing> they arent smart when it comes to security... they dont read the lists etc..
[08:35:21] <flurdoing> with windows its worse because entire families download spam and porn all day long :/
[08:35:24] <Peter> Just because the majority of people that dont know anything about computers use Windows, and dont update.. doesnt mean the OS is inhertiantly bad. if any os gains ground.
[08:35:32] <Peter> Yeah, exactly =)
[08:35:43] <flurdoing> well both are problems i guess
[08:36:03] <mst-_> Ok, I feel that this is coming to "GDI is a part of 32 kernel thunk?" - "So what, you have a webserver in your kernel" discussion
[08:36:18] <mst-_> Let's get back to the point
[08:36:27] <flurdoing> =)
[08:36:51] <flurdoing> manditory AV usage
[08:36:58] <Peter> mst: OH! I was gonna say something about the kitchen sink =)
[08:37:09] <Peter> but, windows webserver is now part of the kernel too.
[08:37:12] * Peter grins
[08:37:28] <flurdoing> i've heard that many multiplayer game servers require users using some anti-cheat application which they proactively check for
[08:37:34] <Peter> flurdoing : like, Gameguard?
[08:37:37] <mst-_> Peter: hey no emacs jokes here please :)
[08:37:49] <mst-_> flurdoing: yes, punkbuster and such.
[08:37:53] * flurdoing shrugs
[08:37:56] <Peter> Those things.. heh.
[08:37:59] <mst-_> flurdoing: the problem is, those are commercial.
[08:38:03] <Peter> Ill be right back, gotta do dishes.
[08:38:07] <reed> ok people
[08:38:11] <Peter> And, those things are *very* easy to break if you arent some script kiddie.
[08:38:12] <reed> we've gotten off topic
[08:38:18] <reed> let's get back to the topic at hand
[08:38:18] <mst-_> Yeah
[08:38:21] <reed> let's design it
[08:38:22] <flurdoing> Peter: point duly noted...
[08:38:27] <reed> and write up how we want to do it
[08:38:33] <flurdoing> it'd be hard to devise such a system for IRC which could not easily be bypassed
[08:38:52] <mst-_> I propose to take off, everyone should think about it, and then we'll re-gather here with notice in advance, discuss and draw concrete statement of intent and go from there.
[08:39:32] <reed> meet when?
[08:39:39] <mst-_> reed: say, weekend
[08:39:47] <flurdoing> someone come to #vh and invite pryz and i =)
[08:40:01] <mst-_> I'll inform pryz directly.
[08:40:41] <flurdoing> hehe ok, inform me directly too unless you dont want me to partake of course
[08:40:49] <mst-_> if you be around
[08:40:55] <mst-_> subscribe to our mailing list!
[08:41:06] <flurdoing> i'm always around... whats the address
[08:41:07] <mst-_> http://lists.irc-unity.org/mailman/listinfo/irc-security_lists.irc-unity.org
[08:41:13] <flurdoing> done
[08:41:39] <mst-_> watch for the notices
[08:41:54] <reed> ok
[08:41:57] <reed> I will post this log to the list
[08:42:13] <reed> when should I stop
[08:42:15] <reed> look above
[08:42:18] <reed> find a good stopping place :p
[08:43:18] <mst-_> ----------- cut here ---------
[08:43:20] <mst-_> :P
--
http://freebsdwiki.org/ - Encrypted mail welcome - keyid 0xBF15490B
"``Brevity is the soul of wit'' said Shakespeare. I say ``Wank!'' Thus I
win."
-- The League Against Tedium
_______________________________________________
public mailing list
public-Hb7ITwsGSD4lroQnaJEqWdi2O/[email protected]
http://lists.blitzed.org/listinfo/public
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQFAtFjoIJm2TL8VSQsRAsZOAKDM4CRSWvKoJCdLLcmOiqci+zPmrQCePctF bsS4C8FXIkJfPHfcqH1BaGM= =kZNi -----END PGP SIGNATURE-----