Re: bopm problem

Andy Smith <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
On Fri, Aug 27, 2004 at 11:25:24PM -0500, Alex McMillen wrote:
> I don't mean to act like a n00b, however this is a huge problem,
> today, I had a botnet attempting to load about 500 total proxies, 300
> of which were caught by bopm and k:lined, however the other 200 were
> not caught and I had to manually ban them. I'm using 3 dnsbls, and
> it's configured "perfectly" but why isn't bopm scanning even some of
> the simplest proxy ports used today to bypass scans? Shouldn't more
> ports be added to bopm's list of ports to scan?

Feel free to start a "common proxy ports" project.  Sad fact is that
such a list would encompass several hundred ports with a few
protocols on each and still wouldn't be much more effective.

All BOPM can ever do is mitigate this problem.  Trying to detect
malware on a remote owned machine was a losing proposition from the
start.

By all means share what works for you.

Incidentally I am still interested in a more general project where
multiple co-operating but not necessarily mutually trusting IRC networks
could somehow share info about abusive IPs and publish it in DNSBL
format.

-- 
Andy Smith -- Occasional BOPM Developer And Support Monkey.  Please copy
all BOPM support queries to the BOPM list, _not_ just directly to me!
If I've helped you with BOPM then please check my wishlist!
http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (FreeBSD)

iD8DBQFBMBhEIJm2TL8VSQsRAorXAKC0Pep6jq2zKo6T1mE+1aKOAqzJBwCguWry
y1Kfz2zTPWHfb4PHsmKzk1A=
=TaqK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.