Re: some strange proxy results
Andy Smith <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Mar 16, 2005 at 02:05:36PM +0000, Craig Edwards wrote: > surprisingly enough this very issue was what bought me to this list a > year ago, and still nothing has been done because they don't consider it > a bug. It is not a bug because it is very simple and obvious how bopm works and it has been documented for years how to avoid the problem you are seeing. > However, i'm still being glined and klined from efnet for having > an open proxy when im a false positive, and you'd think efnet would get > their configuration RIGHT. ongeboren is right in saying it should NOT > just assume an open proxy without checking the connection to the > target_ip beforehand! That's great to just say "should NOT just assume an open proxy" but that is a bit like saying "everything should just work how I want." What makes you think there is any indication whatsoever to BOPM that it is no longer talking to the suspected proxy and has in fact reached the target? Without any such indication (which there ISN'T) all that is left is one of two methods: 1) Check for a string which is unique to the target, can only be produced by the target, and will never be seen anywhere else but the target. Therefore when this string is seen, we know we are talking to the target nopw and the proxying was successful. This is what it is documented to do. 2) Make BOPM send something through the proxy and then make the target check for receipt of that communication, then have it communicate with the BOPM out of band and have BOPM apply a ban then. The target could in fact be a port on the same machine as the BOPM, which the BOPM is listening on. We chose to do (1) because it was so simple and would involve no listening ports, nothing to worry about being firewalled. After all, every IRC admin already has something listening on a port, right? And if they weren't happy with that, well, it is trivial to just set up an inetd service or something to give out a unique string, right? Yes that's right but unfortunately no one seems to be interested in reading the docs and setting up those solutions, even on Blitzed itself. Anyone blocking you from connecting to their IRC network because you run an ircd on port 1080 and they run a BOPM with a generic ircd banner text as the target string is doing so because they can't be bothered to read the docs and either change their string (if their ircd gives a unique banner) or set up a simple echo service. So perhaps we should have done (2) simply to protect IRC admins from themselves. Patches are welcome. I think. Erik? -- Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy all BOPM support queries to the BOPM list, _not_ just directly to me! If I've helped you with BOPM then please check my wishlist! http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (FreeBSD) iD8DBQFCOEJNIJm2TL8VSQsRAlfeAKCVa0877rExRRoHVaLQrp91zOzkBQCbBw8B FmS7uWGntr7Vo606ywry+gc= =/X+r -----END PGP SIGNATURE-----