Re: Question about blacklist entries
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On Monday 01 November 2004 3:34 am, Andy Smith wrote: > On Mon, Nov 01, 2004 at 12:15:16AM -0500, tabris wrote: > > > BTW I don't anyone who has tried setting a PRIVMSG as a > > > kline. It will work but some messages and such may seem strange > > > in that context. > > > > I have. what I have is 4 DNSBLs that do PRIVMSG to the diagnostic > > channel, and only one that does an auto-kline, opm.blitzed. > > Of course it sends two messages then, but that's mostly ok by me. > > Interesting. If you would like to post the relevant parts of your > bopm.conf then I will add it to the BOPM wiki at > http://wiki.blitzed.org/BOPM (or you or anyone else can, but editing > does require a registered nickname on irc.blitzed.org). I'll look into that. > > > What i'd REALLY like is a DEFCON mode that lets me send a command > > to our proxybot[s] that tells it to ban on anything hat matches a > > DNSBL, but most of the time not do so. most of hte time i dont' > > need to autoban on the odd DNSBLs, but if i'm under a proxy/clone > > attack, it would be nice. > > So effectively you would like to be able to reconfigure BOPM without > restarting it? The idea is that I have multiple BOPM bots, located on multiple hosts. that i'd have to login to the shell of, edit the config, and then restart. and there's no way to pull what I do with unreal, which is I have a netwide portion and a local portion. i sync up the netwide portion with rsync and rehash. bopm afaict has no 'include directive'. and as such, reconfiguring 2 or 6 or 12 at a time is a bit much. > > BTW I think you could edit the bopm.conf and then /kill the bot > which would cause it to reconnect to IRC and reread its config. > That wouldn't be very elegant and would entail a few seconds of > downtime for the bot, but it would achieve what you want. > > > Actually what would be nice is to have a blacklist like a cross > > btwn CBL.abuseat.org and OPM. gets lots of contributions from > > automated systems... but expires entries after like a week or two > > from dynamic netblocks. I'm sure it's been mentioned before. > > opm.blitzed.org doesn't have a lot of proxies, as the > > submission/scanning methods are rather narrow, but the other lists > > keep listings years later for dynamic IPs. > > OPM already does expire entries from known dynamic ranges after a > multiple of one day (the multiple starting at 1x and going up > depending on how many times the IP has been reported before). Hmm. mebbe with the discussion in the other thread... > > It is reasonably safe to use CBL as a DNSBL in BOPM. > > There also exists a patch by Mark Bergsma to add whitelist support. > The idea being that you configure many strict DNSBLs and then use > the dynamic IP DNS lists as whitelists plus optionally another DNSWL > of your own to exempt whoever you choose. -- <Culus> Saens demonstrates no less than 3 tcp/ip bugs in 2.2.3