Re: bopm problem

tabris <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Saturday 28 August 2004 12:25 am, Alex McMillen wrote:
> I don't mean to act like a n00b, however this is a huge problem,
> today, I had a botnet attempting to load about 500 total proxies, 300
> of which were caught by bopm and k:lined, however the other 200 were
> not caught and I had to manually ban them. I'm using 3 dnsbls, and
> it's configured "perfectly" but why isn't bopm scanning even some of
> the simplest proxy ports used today to bypass scans? Shouldn't more
> ports be added to bopm's list of ports to scan?
	a) some proxies are undetectable. they have a different IN address than 
OUT address.
	b) proxies can be on ANY port. we can't scan 60000+ ports. would take 
too long, and look like a DoS (and as a matter of fact, some boxes will 
crash scanning just ~1000 ports on them... mind you, they're not 
configged right, but It has happened. either that or the GVSU.edu IT 
dept just hated me). Feel free to add more ports to the config. But you 
may then find that your proxy scanner gets bogged down scanning 200+ 
ports per connected proxy. and there IS a limit on how many can be 
scanned at once (fd limit)
	c) there is no 'simple' proxy port, that phrase makes no sense.
>
> Alex

- --
tabris
- -
Computers don't actually think.
	You just think they think.
		(We think.)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBMAq31U5ZaPMbKQcRAnc3AJ0dqhzAX+pEios87Zsnbq3GgrUpjgCeISNb
t5sXv9Yf8cxbElg6HhtbZWM=
=MjaL
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.