Re: bopm problem
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Saturday 28 August 2004 12:25 am, Alex McMillen wrote: > I don't mean to act like a n00b, however this is a huge problem, > today, I had a botnet attempting to load about 500 total proxies, 300 > of which were caught by bopm and k:lined, however the other 200 were > not caught and I had to manually ban them. I'm using 3 dnsbls, and > it's configured "perfectly" but why isn't bopm scanning even some of > the simplest proxy ports used today to bypass scans? Shouldn't more > ports be added to bopm's list of ports to scan? a) some proxies are undetectable. they have a different IN address than OUT address. b) proxies can be on ANY port. we can't scan 60000+ ports. would take too long, and look like a DoS (and as a matter of fact, some boxes will crash scanning just ~1000 ports on them... mind you, they're not configged right, but It has happened. either that or the GVSU.edu IT dept just hated me). Feel free to add more ports to the config. But you may then find that your proxy scanner gets bogged down scanning 200+ ports per connected proxy. and there IS a limit on how many can be scanned at once (fd limit) c) there is no 'simple' proxy port, that phrase makes no sense. > > Alex - -- tabris - - Computers don't actually think. You just think they think. (We think.) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBMAq31U5ZaPMbKQcRAnc3AJ0dqhzAX+pEios87Zsnbq3GgrUpjgCeISNb t5sXv9Yf8cxbElg6HhtbZWM= =MjaL -----END PGP SIGNATURE-----