RE: help me
"Jubair Hasan" <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Organization | BDiRC |
| Message-ID | <[email protected]> |
kline = "GLINE *@%h :Open Proxy found on your host. Please visit www.blitzed.org/proxy?ip=%i for more information."; I have attached the conf file I am using (I changed the ip and server names) Jubair Hasan -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Andy Smith Sent: Thursday, 13 November 2003 9:36 AM To: [email protected] Subject: Re: [bopm] help me On Thu, Nov 13, 2003 at 09:05:05AM +1100, Jubair Hasan wrote: > The version I am using in bopm-3.1.1(with DNSBL Whitelists support and > HTTP GET proxies scan support), in unrealircd, I am using > unreal3.2beta18(with bopmhelper module) and epona1.4.14 What's your kline setting? -- Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy all BOPM support queries to the BOPM list, _not_ just directly to me! If I've helped you with BOPM then please check my wishlist! http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
bopm.sample.conf
(application/octet-stream, 7.1 KB)
/*
BOPM sample configuration
*/
options {
pidfile = "/home/LifE/bopm/bopm.pid";
negcache = 3600;
dns_fdlimit = 64;
# scanlog = "/home/LifE/bopm/scan.log";
};
IRC {
vhost = "127.0.0.1";
nick = "BOPM";
realname = "Name";
username = "bopm";
server = "myserver.net";
#password = "secret";
port = 6667;
nickserv = "privmsg nickserv :identify tryme";
oper = "bopm tryme";
mode = "+rDShgwlcLkFqpKbnAaNCzWHtZv-G";
away = "away";
channel {
name = "#Opers";
#key = "somekey";
invite = "privmsg chanserv :invite #Opers";
};
connregex = "\\*\\*\\* Notice -- Client connecting: ([^ ]+) \\(([^@]+)@([^\\)]+)\\) \\[([0-9\\.]+)\\].*";
kline = "GLINE *@%h :Open Proxy found on your host. Please visit www.blitzed.org/proxy?ip=%i for more information.";
perform = "PROTOCTL HCN";
};
OPM {
blacklist {
name = "opm.blitzed.org";
type = "A record bitmask";
alert = yes;
ban_unknown = yes;
whitelist = yes;
reply {
1 = "WinGate";
2 = "Socks";
4 = "HTTP";
8 = "Router";
16 = "HTTP POST";
};
kline = "GLINE *@%h :Open proxy found on your host, please visit www.blitzed.org/proxy?ip=%i";
};
blacklist {
name = "dynablock.easynet.nl";
whitelist = yes;
alert = yes;
ban_unknown = yes;
whitelist = yes;
type = "A record reply";
reply {
2 = "Dynamic address";
};
kline = "GLINE *@%h :Open proxy found on your host, please visit www.blitzed.org/proxy?ip=%i";
};
blacklist {
name = "dnsbl.njabl.org";
whitelist = yes;
alert = yes;
ban_unknown = yes;
whitelist = yes;
type = "A record reply";
reply {
9 = "Open proxy";
};
kline = "GLINE *@%h :Open proxy found on your host, please visit www.njabl.org/cgi-bin/lookup.cgi?query=%i";
};
dnsbl_from = "[email protected]";
dnsbl_to = "[email protected]";
sendmail = "/usr/sbin/sendmail";
};
scanner {
name="BOPM";
protocol = HTTP:80;
protocol = HTTP:8080;
protocol = HTTP:3128;
protocol = HTTP:6588;
protocol = SOCKS4:1080;
protocol = SOCKS5:1080;
protocol = SOCKS4:81;
protocol = SOCKS5:81;
protocol = ROUTER:81;
protocol = WINGATE:81;
protocol = HTTPPOST:81;
protocol = ROUTER:23;
protocol = HTTPGET:80;
protocol = HTTPGET:3128;
protocol = HTTPGET:8080;
protocol = WINGATE:23;
protocol = HTTPPOST:80;
protocol = HTTP:80;
protocol = HTTP:8080;
protocol = HTTP:3128;
protocol = HTTP:6588;
protocol = HTTP:22799;
protocol = HTTP:22788;
protocol = HTTP:6565;
protocol = HTTP:8000;
protocol = HTTP:1080;
protocol = HTTP:8082;
protocol = HTTP:2280;
protocol = HTTP:8081;
protocol = HTTP:9877;
protocol = HTTP:2282;
protocol = HTTP:80;
protocol = HTTP:6588;
protocol = HTTP:1080;
protocol = HTTP:8080;
protocol = HTTP:22788;
protocol = HTTP:22799;
protocol = HTTP:8860;
protocol = HTTP:8833;
protocol = HTTP:8281;
protocol = HTTP:8000;
protocol = HTTP:8001;
protocol = HTTP:8002;
protocol = HTTP:81;
protocol = SOCKS4:1080;
protocol = SOCKS5:1080;
protocol = SOCKS4:5124;
protocol = SOCKS5:5124;
protocol = SOCKS4:1813;
protocol = SOCKS5:1813;
protocol = SOCKS4:5262;
protocol = SOCKS5:5262;
protocol = SOCKS4:43736;
protocol = SOCKS4:1813;
protocol = SOCKS5:1813;
protocol = SOCKS4:3086;
protocol = SOCKS5:3086;
protocol = SOCKS4:7441;
protocol = SOCKS5:7441;
protocol = SOCKS4:1080;
protocol = SOCKS5:1080;
protocol = SOCKS4:5104;
protocol = SOCKS5:5104;
protocol = SOCKS4:6225;
protocol = SOCKS5:6225;
protocol = SOCKS4:1976;
protocol = SOCKS5:1976;
protocol = SOCKS4:1075;
protocol = SOCKS5:1075;
protocol = SOCKS4:3086;
protocol = SOCKS5:3086;
protocol = SOCKS4:43736;
protocol = SOCKS5:43736;
protocol = SOCKS4:29938;
protocol = SOCKS5:29938;
protocol = SOCKS4:1976;
protocol = SOCKS5:1976;
protocol = SOCKS4:29938;
protocol = SOCKS5:29938;
protocol = SOCKS4:22788;
protocol = SOCKS5:22788;
protocol = SOCKS4:22799;
protocol = SOCKS5:22799;
vhost = "69.50.166.14";
fd = 512;
max_read = 4096;
timeout = 30;
target_ip = "127.0.0.1";
target_port = 6667;
target_url = "http://www.myweb.net/bopmcheck.txt";
target_string = "4droovDemov-ot@OkTilduntibAvVocneehaidor";
target_string = "-myirc.someirc.net- *** Looking up your hostname...";
#target_string = ":server.yournetwork.org NOTICE AUTH :*** Looking up your hostname...";
target_string = "ERROR :Trying to reconnect too fast.";
target_string = "ERROR :Your host is trying to (re)connect too fast -- throttled.";
};
scanner {
name = "extended";
protocol = HTTP:81;
protocol = HTTP:8000;
protocol = HTTP:8001;
protocol = HTTP:8081;
protocol = HTTPPOST:81;
protocol = HTTPPOST:6588;
protocol = HTTPPOST:4480;
protocol = HTTPPOST:8000;
protocol = HTTPPOST:8001;
protocol = HTTPPOST:8080;
protocol = HTTPPOST:8081;
/*
* IRCnet have seen many socks5 on these ports, more than on the
* standard ports even.
*/
protocol = SOCKS4:4914;
protocol = SOCKS4:6826;
protocol = SOCKS4:7198;
protocol = SOCKS4:7366;
protocol = SOCKS4:9036;
protocol = SOCKS5:4438;
protocol = SOCKS5:5104;
protocol = SOCKS5:5113;
protocol = SOCKS5:5262;
protocol = SOCKS5:5634;
protocol = SOCKS5:6552;
protocol = SOCKS5:6561;
protocol = SOCKS5:7464;
protocol = SOCKS5:7810;
protocol = SOCKS5:8130;
protocol = SOCKS5:8148;
protocol = SOCKS5:8520;
protocol = SOCKS5:8814;
protocol = SOCKS5:9100;
protocol = SOCKS5:9186;
protocol = SOCKS5:9447;
protocol = SOCKS5:9578;
vhost = "127.0.0.1";
fd = 512;
max_read = 4096;
timeout = 30;
target_ip = "127.0.0.1";
target_port = 6667;
target_url = "http://www.myweb.net/bopmcheck.txt";
target_string = "4droovDemov-ot@OkTilduntibAvVocneehaidor";
target_string = "-my.someircirc.net- *** Looking up your hostname..."; //changed the real addresses
#target_string = ":server.yournetwork.org NOTICE AUTH :*** Looking up your hostname...";
target_string = "ERROR :Trying to reconnect too fast.";
target_string = "ERROR :Your host is trying to (re)connect too fast -- throttled.";
};
user {
mask = "*!*@*";
scanner = "httpget";
};
scanner {
name = "httpget";
protocol = HTTPGET:80;
protocol = HTTPGET:3128;
protocol = HTTPGET:8080;
vhost = "69.50.166.14";
fd = 512;
max_read = 4096;
timeout = 30;
target_ip = "127.0.0.1";
target_port = 6667;
target_url = "http://www.myweb.net/bopmcheck.txt";
target_string = "4droovDemov-ot@OkTilduntibAvVocneehaidor";
target_string = "-my.someirc.net- *** Looking up your hostname...";
#target_string = ":server.yournetwork.org NOTICE AUTH :*** Looking up your hostname...";
target_string = "ERROR :Trying to reconnect too fast.";
target_string = "ERROR :Your host is trying to (re)connect too fast -- throttled.";
};
user {
mask = "*!*@*";
scanner = "BOPM";
};
user {
mask = "*!*@*";
scanner = "extended";
};
user {
mask = "*!*@*";
mask = "*!~*@*";
mask = "*!squid@*";
mask = "*!nobody@*";
mask = "*!www-data@*";
mask = "*!cache@*";
mask = "*!CacheFlowS@*";
mask = "*!*@*www*";
mask = "*!*@*proxy*";
mask = "*!*@*cache*";
scanner = "BOPM";
};
exempt {
mask = "*!*@81.17.57.99";
};