Re: Hi, and a couple questions

satmd <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
Hi,

if you want to use one bopm for all connections, have a look in your IRCds 
documentation wether it supports seeing remote connections. That way you 
won't need network-bopm.pl and could have bopm opered and place the kills 
itself (the kline setting is something like a printf() with wildcards after 
all). There is no really need to have bopm connect as a server then. About 
the number of scans of this many users I'd suggest having a local caching 
nameserver and perhaps even using negative results caching (Please look into 
the provided sample configuration of bopm for its possible negative side 
effects). Having one bopm for all servers could have another weakpoint 
besides the large amount of data: You get that server attacked, it is down. 
And it'll be fairly easy to block one single scanner's IP if attackers get 
really hold of the attacking host. I set up a second scanner that'll be 
started manually if the first goes down.

I'm sorry I am not familiar with PleXusIRCd, but if it understands "PROTOCOL 
HTN" and or has the possibility to allow operators to see remote connections 
your chances a high to be able to get rid of network-bopm.pl

satmd
(One may or not know me)

Am Samstag 28 Mai 2005 05:26 schrieb Jeff Lec:
> Hi there, bopm users and developers. I'm lec, an oper on the Rizon irc
> network. We have been having problems with drones/abusive users taking
> advantage of open proxies to load botnets, avoid bans, and generally
> being rude, so we are taking an interest in using BOPM to help secure
> the network. In fact, we currently have it running using the
> network-bopm perl script and a bot loaded on one of our servers. This
> leads to the first of my questions.
>
> We want to have one bopm handle the entire network (around 36k users),
> because many of the linked servers will have AUP violations for scanning
>   remote hosts. Will there be any problem with us making a fairly decent
> number of queries per second to the opm blacklist dns? We'll be setting
> the one bot to scan, and will be happy to repopt additional open proxies
> that we come across.
>
> This leads to the next question. Right now, we're using the
> network-bopm.pl script and a bopm that relies on services (operserv, to
> place AKILLS (global klines). We want to have bopm be independent of
> services and not relying on a perl script to handle all the connection
> parsing, so I am currently working on getting bopm to connect as a
> server directly and handle all the connection parsing and kills itself.
>   It will be running on one of the hosts that allows scanning. Do you
> have any recommendationsto help the one bot handle the network worth of
> connections? See any problems with doing it?
>
> I'd appreciate any advice I can get, since I'm fairly new to bopm.
> thanks in advance!
>
> lec
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.