Re: BOPM Scanner false positive

Andy Smith <[email protected]> Fri, 13 Jan 2006 09:41:18 +0000
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
On Thu, Jan 12, 2006 at 08:03:46PM +0100, Christophe Meron wrote:
> We've noticed that there's a false positive with the open HTTP
> proxy detection:
> 
>  Client exiting: whitehat ([email protected]) [User has been
>  banned from EuropNet (Open proxy found on your host. Please visit
>  www.blitzed.org/proxy?ip=194.146.227.87 for more information.)]
> 
> Open http proxy on a shell provider seems a little strange (possible
> but strange :) to me so i checked:
> 
> jan 12 01:16:02 BOPM       OPEN PROXY ->
> [email protected] 194.146.227.87:8080 (HTTP) [default]
> 
> But that port port seems to be binded to a private ircd, not an open
> http proxy  

Looks like the BOPM on the EuropNet server has its target_string
configured with a string that is too common, and that string appears
in the output given by the ircd on 194.146.227.87:8080.  This is
mentioned in BOPM's docs and inline in the comments of the conf
file.

It's not a false positive as such because BOPM is doing exactly as
you tell it (banning when it sees the configured target_string).

-- 
Andy Smith -- Occasional BOPM Developer And Support Monkey.  Please copy
all BOPM support queries to the BOPM list, _not_ just directly to me!
If I've helped you with BOPM then please check my wishlist!
http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDx3W+IJm2TL8VSQsRAvxrAJsG5/XAgM9s+Ck8rh7E2M+tFt+0BACfSMGY
4in4N3+1Mwdz1aHlavmzXlU=
=CHTX
-----END PGP SIGNATURE-----