Re: Leak in BOPM
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sunday 22 August 2004 5:33 pm, Andy Smith wrote: > On Sun, Aug 22, 2004 at 04:00:59PM -0400, tabris wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > On Sunday 22 August 2004 3:13 pm, Andy Smith wrote: > > > On Sun, Aug 22, 2004 at 12:02:28PM -0700, Erik Fears wrote: > > > > Are you sure this is a leak and not the scan queue filling up. > > > > There is no max limit on the scan queue, so if your scanner > > > > can't keep up then it will quickly fill up your memory. > > > > Hmmm. is there an easy way to run 2 or 3 'central' BOPMs that each > > scan a set of servers? I can't put BOPMs on all the leaves, partly > > b/c I don't operate all of the leaves. > > Unless your network has tens of thousands of users, or your scanning > machine is very low on resources, there should be no need. Tell us > what the connect rate is, and also what you have your maximum number > of fds set to, both in the bopm.conf it was exceeding the limit, so i set it down to 384 per scanner, default and extended. I think I can up that to 480 each. The bopm runs inside the same shell acct as the ircd. > and in "ulimit -a" from the > shell. [wcshells-irc@aphrodite etc]$ ulimit -n 1024 > > > > Yes, tabris, please let us know these stats: Ok, this is only after about 3 hours (as it says). I'll probably have to get back to you again after 24 hours. it may also have mattered that at the time, we had twice as many users, most of which various nasty bots we had to setup various filters for. 18:40:38 <+WCProxyBot> Uptime: 2 hours, 48 minutes, 19 seconds 18:40:38 <+WCProxyBot> DNSBL: 10 successful lookups from dnsbl.njabl.org 18:40:38 <+WCProxyBot> DNSBL: 5 successful lookups from cbl.abuseat.org 18:40:38 <+WCProxyBot> Number of connects: 1596 (9.48/minute) I'd have to estimate, but i've seen the connect rate exceed 20/second, esp with lots of bots connecting/disconnecting. It's not so bad now after removing most of those bots. > > > > Hmm. I'll get back to you with those in a couple hours. I had the > > bot set with umode d b/c of how noisy the stats channel is. (and > > i'll stop the periodic KILLs). > > > > Any chance we can change the trigger to something like !stat or > > !bopm stat ? (yes, i'm sure I could hack the code, but I am > > thinking I might not be the only one to care) > > That sounds a bit mad as it would only really help you if no one is > in the stats channel. In that case why not just ask for an option > to make bopm run silently only logging this stuff to file.. Huh? we have ppl in the stats channel. but it can get VERY noisy in there (and heck, always is busy). so i didn't want to have it listen to ConnectServ and OperServ, since it doesn't need to care abut them. We don't talk in the stats channel. just observe. > > Anyway try "!all stat" and "!all fdstat". aah. thank you. that should help. > > > One idea from a friend is a combined nmap/bopm, that first scans > > for open ports, filters out a couple of the more obvious non-proxy > > ports (say 22, 25, 110, 135-139 etc), then scans all of them. I > > think it might take too long to scan, but it is an idea anyway. > > Needs root. Will generate more abuse reports. Hmm. wasn't intending to use the root only ops. It will cause more abuse reports despite the fact that only users that connect get scanned (I see it as possible, but not fully sure why)? I'll pass any more comments on this to my friend. - -- tabris - - Absence is to love what wind is to fire. It extinguishes the small, it enkindles the great. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBKSOE1U5ZaPMbKQcRAvjqAJ9zRu7dQVf493n7+V0oykgQomdi5QCgmP8j WJ6qCl0G4R6hr5MwUi4sqQA= =PsSw -----END PGP SIGNATURE-----