Re: Leak in BOPM
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sunday 22 August 2004 7:55 pm, Andy Smith wrote: > On Sun, Aug 22, 2004 at 06:51:47PM -0400, tabris wrote: > > Ok, this is only after about 3 hours (as it says). I'll probably > > have to get back to you again after 24 hours. it may also have > > mattered that at the time, we had twice as many users, most of > > which various nasty bots we had to setup various filters for. > > 18:40:38 <+WCProxyBot> Uptime: 2 hours, 48 minutes, 19 seconds > > 18:40:38 <+WCProxyBot> DNSBL: 10 successful lookups from > > dnsbl.njabl.org 18:40:38 <+WCProxyBot> DNSBL: 5 successful lookups > > from cbl.abuseat.org 18:40:38 <+WCProxyBot> Number of connects: > > 1596 (9.48/minute) > > > > I'd have to estimate, but i've seen the connect rate exceed > > 20/second, esp with lots of bots connecting/disconnecting. It's not > > so bad now after removing most of those bots. > > So what's the fdstat? right now... quite manageable. 20:00:39 <@tabris> !all stats 20:00:39 <+WCProxyBot> Uptime: 4 hours, 8 minutes, 20 seconds 20:00:39 <+WCProxyBot> DNSBL: 18 successful lookups from dnsbl.njabl.org 20:00:39 <+WCProxyBot> DNSBL: 9 successful lookups from cbl.abuseat.org 20:00:39 <+WCProxyBot> Number of connects: 2342 (9.43/minute) 20:00:41 <@tabris> !all fdstat 20:00:41 <+WCProxyBot> Total open FD: 60/1024 Couple minutes later 20:09:44 <@tabris> !all fdstat 20:09:44 <+WCProxyBot> Total open FD: 127/1024 > even 20/second isn't that much, hmm... 20 connects, 56 protocol/port combinations (I removed the HTTPPOST protocol as we have ping cookies). VM size is still slowly growing in size (doesn't look like much now tho. I've seen worse) Starts at approx 730kb 3 hours ago it was approx 800 right now it's 856 > > > > > One idea from a friend is a combined nmap/bopm, that first > > > > scans for open ports, filters out a couple of the more obvious > > > > non-proxy ports (say 22, 25, 110, 135-139 etc), then scans all > > > > of them. I think it might take too long to scan, but it is an > > > > idea anyway. > > > > > > Needs root. Will generate more abuse reports. > > > > Hmm. wasn't intending to use the root only ops. > > SYN scanning is a root-only operation. Hmm. I wasn't thinking of that... just going for a regular connect() > > > It will cause more > > abuse reports despite the fact that only users that connect get > > scanned (I see it as possible, but not fully sure why)? > > A SYN scan of all 65534 ports looks more suspicious than a connect() > scan of several hundred. Point. even everything under 32000 is still too much. - -- tabris - - "By golly, I'm beginning to think Linux really *is* the best thing since sliced bread." (By Vance Petree, Virginia Power) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBKTYs1U5ZaPMbKQcRApCKAJ9sN+dYLfyR5+0yVNepbuge/lXupgCgoAuW zYf+qICnJ1kVo1tS5NPRkDw= =tRZW -----END PGP SIGNATURE-----