Re: some strange proxy results

Andy Smith <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
On Wed, Mar 16, 2005 at 02:05:36PM +0000, Craig Edwards wrote:
> surprisingly enough this very issue was what bought me to this list a
> year ago, and still nothing has been done because they don't consider it
> a bug.

It is not a bug because it is very simple and obvious how bopm works
and it has been documented for years how to avoid the problem you
are seeing.

> However, i'm still being glined and klined from efnet for having
> an open proxy when im a false positive, and you'd think efnet would get
> their configuration RIGHT. ongeboren is right in saying it should NOT
> just assume an open proxy without checking the connection to the
> target_ip beforehand!

That's great to just say "should NOT just assume an open proxy" but
that is a bit like saying "everything should just work how I want."

What makes you think there is any indication whatsoever to BOPM that
it is no longer talking to the suspected proxy and has in fact
reached the target?

Without any such indication (which there ISN'T) all that is left is
one of two methods:

1) Check for a string which is unique to the target, can only be
   produced by the target, and will never be seen anywhere else but
   the target.  Therefore when this string is seen, we know we are
   talking to the target nopw and the proxying was successful.  This
   is what it is documented to do.

2) Make BOPM send something through the proxy and then make the
   target check for receipt of that communication, then have it
   communicate with the BOPM out of band and have BOPM apply a ban
   then.  The target could in fact be a port on the same machine as
   the BOPM, which the BOPM is listening on.

We chose to do (1) because it was so simple and would involve no
listening ports, nothing to worry about being firewalled.  After
all, every IRC admin already has something listening on a port,
right?  And if they weren't happy with that, well, it is trivial to
just set up an inetd service or something to give out a unique
string, right?  Yes that's right but unfortunately no one seems to
be interested in reading the docs and setting up those solutions,
even on Blitzed itself.

Anyone blocking you from connecting to their IRC network because you
run an ircd on port 1080 and they run a BOPM with a generic ircd
banner text as the target string is doing so because they can't be
bothered to read the docs and either change their string (if their
ircd gives a unique banner) or set up a simple echo service.

So perhaps we should have done (2) simply to protect IRC admins
from themselves.  Patches are welcome.  I think.  Erik?

-- 
Andy Smith -- Occasional BOPM Developer And Support Monkey.  Please copy
all BOPM support queries to the BOPM list, _not_ just directly to me!
If I've helped you with BOPM then please check my wishlist!
http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iD8DBQFCOEJNIJm2TL8VSQsRAlfeAKCVa0877rExRRoHVaLQrp91zOzkBQCbBw8B
FmS7uWGntr7Vo606ywry+gc=
=/X+r
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.