Re: Modifying scans done on certain types of hosts
"m3lk0rz ..." <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
>On Tue, Jul 13, 2004 at 08:53:47AM -0700, m3lk0rz ... wrote: > > How might one go about defining the user portion of the .conf file for >BOPM > > so that it would do the following: > > > > - All users are scanned with the "default" scanner, then... > > > > - Those who do not match criteria of being a dialup/dynamic host (ie. > > *!*@*.dialup.*, *!*@*.dynamic.*, etc.) are not checked with the >"extended" > > scanner, but everybody else is. > >I don't believe there is a way to specify a negative match, only a >positive. Can I ask why you need to do this? As far as I can see >your scheme has a number of problems: > >- Proxies are still found even on the most short-lived of dialup > connections. > >- ISPs are not very consistent with their naming schemes, often > including terms like "dialup" and "dynamic" for both short-lived > dialups and arbitrarily long DSL leases. They even sometimes end > up giving dynamic-looking hostnames to static business SDSL unless > the customer pays more or shouts a lot. That's interesting - I've never heard of ISPs doing something like that... > >- Reverse DNS isn't always there. Right, though this wasn't something that was an absolute neccessity. It was just curious as to how I could do this as an easy way to limit the amount of scanning done. Since these short-lived dialup connections are not likely to be among the proxies that troublemakers exploit, I feel that it would be sufficient to just scan them for the most common proxies. _________________________________________________________________ FREE pop-up blocking with the new MSN Toolbar get it now! http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/