Re: Question about blacklist entries
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 28 October 2004 4:29 am, Andy Smith wrote:
> On Wed, Oct 27, 2004 at 06:37:00PM -0700, m3lk0rz ... wrote:
> > Would it be possible to have an entry for one blacklist check that
> > would, let's say spawn an alert in the BOPM channel for anything
> > detected by response code 1, but have it ban anything detected by
> > response code 2?
> >
> > aka something like:
> > reply {
> > 1 = "Suspected proxy";
> > kline = "PRIVMSG #chan ...";
> > 2 = "Confirmed proxy";
> > kline = "GLINE ...";
> > };
>
> Yes. See the example config file, ask further questions if it's
> still not clear.
>
> BTW I don't anyone who has tried setting a PRIVMSG as a
> kline. It will work but some messages and such may seem strange in
> that context.
I have. what I have is 4 DNSBLs that do PRIVMSG to the diagnostic
channel, and only one that does an auto-kline, opm.blitzed.
Of course it sends two messages then, but that's mostly ok by me.
What i'd REALLY like is a DEFCON mode that lets me send a command to
our proxybot[s] that tells it to ban on anything hat matches a DNSBL,
but most of the time not do so. most of hte time i dont' need to
autoban on the odd DNSBLs, but if i'm under a proxy/clone attack, it
would be nice.
Actually what would be nice is to have a blacklist like a cross btwn
CBL.abuseat.org and OPM. gets lots of contributions from automated
systems... but expires entries after like a week or two from dynamic
netblocks. I'm sure it's been mentioned before. opm.blitzed.org doesn't
have a lot of proxies, as the submission/scanning methods are rather
narrow, but the other lists keep listings years later for dynamic IPs.
--
tabris
-
To err is human,
To purr feline.
-- Robert Byrne