Re: bopm problem

"Tim Syratt" <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
Hi All,

If someone has the time & resources to start either a 'common proxy ports'
project or a shared DNSBL of banned users, AustNET (www.austnet.org) would
like to express their intrest and assistance.

Regs,
Tim

> On Fri, Aug 27, 2004 at 11:25:24PM -0500, Alex McMillen wrote:
>> I don't mean to act like a n00b, however this is a huge problem,
>> today, I had a botnet attempting to load about 500 total proxies, 300
>> of which were caught by bopm and k:lined, however the other 200 were
>> not caught and I had to manually ban them. I'm using 3 dnsbls, and
>> it's configured "perfectly" but why isn't bopm scanning even some of
>> the simplest proxy ports used today to bypass scans? Shouldn't more
>> ports be added to bopm's list of ports to scan?
>
> Feel free to start a "common proxy ports" project.  Sad fact is that
> such a list would encompass several hundred ports with a few
> protocols on each and still wouldn't be much more effective.
>
> All BOPM can ever do is mitigate this problem.  Trying to detect
> malware on a remote owned machine was a losing proposition from the
> start.
>
> By all means share what works for you.
>
> Incidentally I am still interested in a more general project where
> multiple co-operating but not necessarily mutually trusting IRC networks
> could somehow share info about abusive IPs and publish it in DNSBL
> format.
>
> --
> Andy Smith -- Occasional BOPM Developer And Support Monkey.  Please copy
> all BOPM support queries to the BOPM list, _not_ just directly to me!
> If I've helped you with BOPM then please check my wishlist!
> http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
>


-- 
Regards,
Tim Syratt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.