Re: bopm problem
Andy Smith <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 27, 2004 at 11:25:24PM -0500, Alex McMillen wrote: > I don't mean to act like a n00b, however this is a huge problem, > today, I had a botnet attempting to load about 500 total proxies, 300 > of which were caught by bopm and k:lined, however the other 200 were > not caught and I had to manually ban them. I'm using 3 dnsbls, and > it's configured "perfectly" but why isn't bopm scanning even some of > the simplest proxy ports used today to bypass scans? Shouldn't more > ports be added to bopm's list of ports to scan? Feel free to start a "common proxy ports" project. Sad fact is that such a list would encompass several hundred ports with a few protocols on each and still wouldn't be much more effective. All BOPM can ever do is mitigate this problem. Trying to detect malware on a remote owned machine was a losing proposition from the start. By all means share what works for you. Incidentally I am still interested in a more general project where multiple co-operating but not necessarily mutually trusting IRC networks could somehow share info about abusive IPs and publish it in DNSBL format. -- Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy all BOPM support queries to the BOPM list, _not_ just directly to me! If I've helped you with BOPM then please check my wishlist! http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (FreeBSD) iD8DBQFBMBhEIJm2TL8VSQsRAorXAKC0Pep6jq2zKo6T1mE+1aKOAqzJBwCguWry y1Kfz2zTPWHfb4PHsmKzk1A= =TaqK -----END PGP SIGNATURE-----