Re: Question about blacklist entries

tabris <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
On Monday 01 November 2004 3:34 am, Andy Smith wrote:
> On Mon, Nov 01, 2004 at 12:15:16AM -0500, tabris wrote:
> > > BTW I don't anyone who has tried setting a PRIVMSG as a
> > > kline.  It will work but some messages and such may seem strange
> > > in that context.
> >
> > 	I have. what I have is 4 DNSBLs that do PRIVMSG to the diagnostic
> > channel, and only one that does an auto-kline, opm.blitzed.
> > 	Of course it sends two messages then, but that's mostly ok by me.
>
> Interesting.  If you would like to post the relevant parts of your
> bopm.conf then I will add it to the BOPM wiki at
> http://wiki.blitzed.org/BOPM (or you or anyone else can, but editing
> does require a registered nickname on irc.blitzed.org).
	I'll look into that.
>
> > 	What i'd REALLY like is a DEFCON mode that lets me send a command
> > to our proxybot[s] that tells it to ban on anything hat matches a
> > DNSBL, but most of the time not do so. most of hte time i dont'
> > need to autoban on the odd DNSBLs, but if i'm under a proxy/clone
> > attack, it would be nice.
>
> So effectively you would like to be able to reconfigure BOPM without
> restarting it?
	The idea is that I have multiple BOPM bots, located on multiple hosts. 
that i'd have to login to the shell of, edit the config, and then 
restart. and there's no way to pull what I do with unreal, which is I 
have a netwide portion and a local portion. i sync up the netwide 
portion with rsync and rehash. bopm afaict has no 'include directive'.

	and as such, reconfiguring 2 or 6 or 12 at a time is a bit much.
>
> BTW I think you could edit the bopm.conf and then /kill the bot
> which would cause it to reconnect to IRC and reread its config.
> That wouldn't be very elegant and would entail a few seconds of
> downtime for the bot, but it would achieve what you want.
>
> > 	Actually what would be nice is to have a blacklist like a cross
> > btwn CBL.abuseat.org and OPM. gets lots of contributions from
> > automated systems... but expires entries after like a week or two
> > from dynamic netblocks. I'm sure it's been mentioned before.
> > opm.blitzed.org doesn't have a lot of proxies, as the
> > submission/scanning methods are rather narrow, but the other lists
> > keep listings years later for dynamic IPs.
>
> OPM already does expire entries from known dynamic ranges after a
> multiple of one day (the multiple starting at 1x and going up
> depending on how many times the IP has been reported before).
	Hmm. mebbe with the discussion in the other thread...
>
> It is reasonably safe to use CBL as a DNSBL in BOPM.
>
> There also exists a patch by Mark Bergsma to add whitelist support.
> The idea being that you configure many strict DNSBLs and then use
> the dynamic IP DNS lists as whitelists plus optionally another DNSWL
> of your own to exempt whoever you choose.

-- 
<Culus> Saens demonstrates no less than 3 tcp/ip bugs in 2.2.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.