Re: False positive?

DelGurth <[email protected]> Wed, 29 Mar 2006 08:05:53 +0200
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
On 3/28/06, Alexey <[email protected]> wrote:
> 1) Try to add some logs to this mail ;)

I didn't think that could be usefull, but here goes

[Mar 28 16:21:35 2006] SCAN -> All tests on
[email protected] complete.
[Mar 28 16:21:55 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm
:*** Notice -- Client connecting at fr2.irc.delgurth.com: Titiz
([email protected])
[82.122.204.148] {0}
[Mar 28 16:21:55 2006] IRC REGEX -> Regular expression caught
connection notice. Parsing.
[Mar 28 16:21:55 2006] IRC REGEX -> Parsed
[email protected]
[82.122.204.148] from connection notice.
[Mar 28 16:21:55 2006] DNSBL -> Passed
'148.204.122.82.opm.blitzed.org' to resolver
[Mar 28 16:21:55 2006] SCAN -> Passing
[email protected] to
scanner [default]
[Mar 28 16:21:55 2006] DNSBL -> Lookup result for
[email protected]
(148.204.122.82.opm.blitzed.org) 0.0.0.0 (error: 3)
[Mar 28 16:21:56 2006] IRC SEND -> GLINE
+*@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr 6h :Open Proxy found
on your host. Please visit www.blitzed.org/proxy?ip=82.122.204.148 for
more information.
[Mar 28 16:21:56 2006] DNSBL -> Sending following email:
From: bopm <[email protected]>
To: [email protected]
Subject: BOPM Report
X-BOPM-Version: 3.1.2

SOCKS4: 82.122.204.148:1080

:nl1.irc.delgurth.com NOTICE bopm :*** Notice -- Client connecting at
fr2.irc.delgurth.com: Titiz
([email protected])
[82.122.204.148] {0}


[Mar 28 16:21:57 2006] DNSBL -> Sent report to
[email protected] [82.122.204.148]
[Mar 28 16:21:57 2006] IRC SEND -> PRIVMSG ##opers :OPEN PROXY ->
[email protected]
82.122.204.148:1080 (SOCKS4) [default]
[Mar 28 16:21:57 2006] SCAN -> OPEN PROXY
[email protected]
82.122.204.148:1080 (SOCKS4) [default]
[Mar 28 16:21:57 2006] SCAN -> Scan 82.122.204.148 [default] completed
[Mar 28 16:21:57 2006] SCAN -> All tests on
[email protected] complete.
[Mar 28 16:21:57 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm
:*** G:Line added for *@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr
on Tue Mar 28 16:
21:56 2006 GMT (from [email protected] to expire
at Tue Mar 28 22:21:56 2006 GMT: Open Proxy found on your host. Please
visit www.blitze
d.org/proxy?ip=82.122.204.148 for more information.)
[Mar 28 16:21:57 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm
:*** Notice -- Client exiting at fr2.irc.delgurth.com: Titiz
(VilainZ@AMarseille-151-1-1
3-148.w82-122.abo.wanadoo.fr) [User has been banned from Hyperiums
(Open Proxy found on your host. Please visit
www.blitzed.org/proxy?ip=82.122.204.148 for m
ore information.)] [82.122.204.148]


Then I removed the gline:

[Mar 28 16:22:18 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm
:[email protected] removed G:Line
*@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr (set at Tue Mar 28
16:21:56 2006 - reason: Open Proxy found on your host. Please visit
www.blitzed.org/proxy?ip=82.122.204.148 for more information.)
[Mar 28 16:24:10 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm
:*** Notice -- Client connecting at fr2.irc.delgurth.com: Titiz
(VilainZ@AMarseille-151-
1-13-148.w82-122.abo.wanadoo.fr) [82.122.204.148] {0}
[Mar 28 16:24:10 2006] IRC REGEX -> Regular expression caught
connection notice. Parsing.
[Mar 28 16:24:10 2006] IRC REGEX -> Parsed
[email protected]
[82.122.204.148] from connection notice.
[Mar 28 16:24:10 2006] DNSBL -> Passed
'148.204.122.82.opm.blitzed.org' to resolver
[Mar 28 16:24:10 2006] SCAN -> Passing
[email protected] to
scanner [default]
[Mar 28 16:24:10 2006] DNSBL -> Lookup result for
[email protected]
(148.204.122.82.opm.blitzed.org) 0.0.0.0 (error: 3)
[Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:1080
(SOCKS4) [default] (39 bytes read)
[Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:1080
(SOCKS5) [default] (39 bytes read)
[Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:23
(WINGATE) [default] (39 bytes read)
[Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:23
(ROUTER) [default] (39 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:80
(HTTP) [default] (0 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Negotiation timed out
82.122.204.148:8080 (HTTP) [default] (0 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Negotiation timed out
82.122.204.148:3128 (HTTP) [default] (0 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Negotiation timed out
82.122.204.148:6588 (HTTP) [default] (0 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Negotiation timed out
82.122.204.148:4480 (HTTP) [default] (0 bytes read)
[Mar 28 16:24:40 2006] SCAN -> Scan 82.122.204.148 [default] completed
[Mar 28 16:24:40 2006] SCAN -> All tests on
[email protected] complete.


All I can see here is that bopm received 39 bytes of data the second
time, but no longer a positive.


> 2) Try to block incoming connections from "external IPs" using firewall

He could try blocking incoming connections from the scanner ip-address I guess.

> 3) Try to add this CCProxy IP address to "exempt" section in BOPM config

That's not going to work, since he's getting a new IP address quite often.


@eric

No he's not running an ircd, and as I said, trying to connect to his
host after he's banned I get: 83.160.25.144 is external user, blocked

And this is my list of matching strings, even if he has a ircd, he
needs to use the same name for his ircd as I do to make it give a
false positive.

target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Looking up
your hostname...";
target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Found your hostname";
target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Found your
hostname (cached)";
target_string = "(Throttled: Reconnecting too fast) -Email
[email protected] for more information.";

Regards,
Wessel van Norel