Re: Leak in BOPM

tabris <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sunday 22 August 2004 7:55 pm, Andy Smith wrote:
> On Sun, Aug 22, 2004 at 06:51:47PM -0400, tabris wrote:
> > 	Ok, this is only after about 3 hours (as it says). I'll probably
> > have to get back to you again after 24 hours. it may also have
> > mattered that at the time, we had twice as many users, most of
> > which various nasty bots we had to setup various filters for.
> > 18:40:38 <+WCProxyBot> Uptime: 2 hours, 48 minutes, 19 seconds
> > 18:40:38 <+WCProxyBot> DNSBL: 10 successful lookups from
> > dnsbl.njabl.org 18:40:38 <+WCProxyBot> DNSBL: 5 successful lookups
> > from cbl.abuseat.org 18:40:38 <+WCProxyBot> Number of connects:
> > 1596 (9.48/minute)
> >
> > 	I'd have to estimate, but i've seen the connect rate exceed
> > 20/second, esp with lots of bots connecting/disconnecting. It's not
> > so bad now after removing most of those bots.
>
> So what's the fdstat?
right now... quite manageable.
20:00:39 <@tabris> !all stats
20:00:39 <+WCProxyBot> Uptime: 4 hours, 8 minutes, 20 seconds
20:00:39 <+WCProxyBot> DNSBL: 18 successful lookups from dnsbl.njabl.org
20:00:39 <+WCProxyBot> DNSBL: 9 successful lookups from cbl.abuseat.org
20:00:39 <+WCProxyBot> Number of connects: 2342 (9.43/minute)
20:00:41 <@tabris> !all fdstat
20:00:41 <+WCProxyBot> Total open FD: 60/1024

Couple minutes later
20:09:44 <@tabris> !all fdstat
20:09:44 <+WCProxyBot> Total open FD: 127/1024
> even 20/second isn't that much, hmm... 
20 connects, 56 protocol/port combinations (I removed the HTTPPOST 
protocol as we have ping cookies).

VM size is still slowly growing in size (doesn't look like much now tho. 
I've seen worse)
Starts at approx 730kb
3 hours ago it was approx 800
right now it's 856

>
> > > > One idea from a friend is a combined nmap/bopm, that first
> > > > scans for open ports, filters out a couple of the more obvious
> > > > non-proxy ports (say 22, 25, 110, 135-139 etc), then scans all
> > > > of them. I think it might take too long to scan, but it is an
> > > > idea anyway.
> > >
> > > Needs root.  Will generate more abuse reports.
> >
> > 	Hmm. wasn't intending to use the root only ops.
>
> SYN scanning is a root-only operation.
	Hmm. I wasn't thinking of that... just going for a regular connect()
>
> > It will cause more
> > abuse reports despite the fact that only users that connect get
> > scanned (I see it as possible, but not fully sure why)?
>
> A SYN scan of all 65534 ports looks more suspicious than a connect()
> scan of several hundred.
	Point. even everything under 32000 is still too much.

- --
tabris
- -
"By golly, I'm beginning to think Linux really *is* the best thing since
sliced bread."
(By Vance Petree, Virginia Power)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBKTYs1U5ZaPMbKQcRApCKAJ9sN+dYLfyR5+0yVNepbuge/lXupgCgoAuW
zYf+qICnJ1kVo1tS5NPRkDw=
=tRZW
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.