Re: bopm problem
"Tim Syratt" <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
Hi All, If someone has the time & resources to start either a 'common proxy ports' project or a shared DNSBL of banned users, AustNET (www.austnet.org) would like to express their intrest and assistance. Regs, Tim > On Fri, Aug 27, 2004 at 11:25:24PM -0500, Alex McMillen wrote: >> I don't mean to act like a n00b, however this is a huge problem, >> today, I had a botnet attempting to load about 500 total proxies, 300 >> of which were caught by bopm and k:lined, however the other 200 were >> not caught and I had to manually ban them. I'm using 3 dnsbls, and >> it's configured "perfectly" but why isn't bopm scanning even some of >> the simplest proxy ports used today to bypass scans? Shouldn't more >> ports be added to bopm's list of ports to scan? > > Feel free to start a "common proxy ports" project. Sad fact is that > such a list would encompass several hundred ports with a few > protocols on each and still wouldn't be much more effective. > > All BOPM can ever do is mitigate this problem. Trying to detect > malware on a remote owned machine was a losing proposition from the > start. > > By all means share what works for you. > > Incidentally I am still interested in a more general project where > multiple co-operating but not necessarily mutually trusting IRC networks > could somehow share info about abusive IPs and publish it in DNSBL > format. > > -- > Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy > all BOPM support queries to the BOPM list, _not_ just directly to me! > If I've helped you with BOPM then please check my wishlist! > http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9 > -- Regards, Tim Syratt