Re: Question about blacklist entries
Andy Smith <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Nov 01, 2004 at 12:15:16AM -0500, tabris wrote: > > BTW I don't anyone who has tried setting a PRIVMSG as a > > kline. It will work but some messages and such may seem strange in > > that context. > I have. what I have is 4 DNSBLs that do PRIVMSG to the diagnostic > channel, and only one that does an auto-kline, opm.blitzed. > Of course it sends two messages then, but that's mostly ok by me. Interesting. If you would like to post the relevant parts of your bopm.conf then I will add it to the BOPM wiki at http://wiki.blitzed.org/BOPM (or you or anyone else can, but editing does require a registered nickname on irc.blitzed.org). > What i'd REALLY like is a DEFCON mode that lets me send a command to > our proxybot[s] that tells it to ban on anything hat matches a DNSBL, > but most of the time not do so. most of hte time i dont' need to > autoban on the odd DNSBLs, but if i'm under a proxy/clone attack, it > would be nice. So effectively you would like to be able to reconfigure BOPM without restarting it? BTW I think you could edit the bopm.conf and then /kill the bot which would cause it to reconnect to IRC and reread its config. That wouldn't be very elegant and would entail a few seconds of downtime for the bot, but it would achieve what you want. > Actually what would be nice is to have a blacklist like a cross btwn > CBL.abuseat.org and OPM. gets lots of contributions from automated > systems... but expires entries after like a week or two from dynamic > netblocks. I'm sure it's been mentioned before. opm.blitzed.org doesn't > have a lot of proxies, as the submission/scanning methods are rather > narrow, but the other lists keep listings years later for dynamic IPs. OPM already does expire entries from known dynamic ranges after a multiple of one day (the multiple starting at 1x and going up depending on how many times the IP has been reported before). It is reasonably safe to use CBL as a DNSBL in BOPM. There also exists a patch by Mark Bergsma to add whitelist support. The idea being that you configure many strict DNSBLs and then use the dynamic IP DNS lists as whitelists plus optionally another DNSWL of your own to exempt whoever you choose. -- Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy all BOPM support queries to the BOPM list, _not_ just directly to me! If I've helped you with BOPM then please check my wishlist! http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (FreeBSD) iD4DBQFBhfUiIJm2TL8VSQsRAhJ/AJ901zEkj848uM3G3bTQnkNTjoynoACXcbmp dHerLfqXBYq26FnwHVumdg== =UVJD -----END PGP SIGNATURE-----