Re: False positive?
DelGurth <[email protected]> Wed, 29 Mar 2006 08:05:53 +0200
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
On 3/28/06, Alexey <[email protected]> wrote: > 1) Try to add some logs to this mail ;) I didn't think that could be usefull, but here goes [Mar 28 16:21:35 2006] SCAN -> All tests on [email protected] complete. [Mar 28 16:21:55 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm :*** Notice -- Client connecting at fr2.irc.delgurth.com: Titiz ([email protected]) [82.122.204.148] {0} [Mar 28 16:21:55 2006] IRC REGEX -> Regular expression caught connection notice. Parsing. [Mar 28 16:21:55 2006] IRC REGEX -> Parsed [email protected] [82.122.204.148] from connection notice. [Mar 28 16:21:55 2006] DNSBL -> Passed '148.204.122.82.opm.blitzed.org' to resolver [Mar 28 16:21:55 2006] SCAN -> Passing [email protected] to scanner [default] [Mar 28 16:21:55 2006] DNSBL -> Lookup result for [email protected] (148.204.122.82.opm.blitzed.org) 0.0.0.0 (error: 3) [Mar 28 16:21:56 2006] IRC SEND -> GLINE +*@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr 6h :Open Proxy found on your host. Please visit www.blitzed.org/proxy?ip=82.122.204.148 for more information. [Mar 28 16:21:56 2006] DNSBL -> Sending following email: From: bopm <[email protected]> To: [email protected] Subject: BOPM Report X-BOPM-Version: 3.1.2 SOCKS4: 82.122.204.148:1080 :nl1.irc.delgurth.com NOTICE bopm :*** Notice -- Client connecting at fr2.irc.delgurth.com: Titiz ([email protected]) [82.122.204.148] {0} [Mar 28 16:21:57 2006] DNSBL -> Sent report to [email protected] [82.122.204.148] [Mar 28 16:21:57 2006] IRC SEND -> PRIVMSG ##opers :OPEN PROXY -> [email protected] 82.122.204.148:1080 (SOCKS4) [default] [Mar 28 16:21:57 2006] SCAN -> OPEN PROXY [email protected] 82.122.204.148:1080 (SOCKS4) [default] [Mar 28 16:21:57 2006] SCAN -> Scan 82.122.204.148 [default] completed [Mar 28 16:21:57 2006] SCAN -> All tests on [email protected] complete. [Mar 28 16:21:57 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm :*** G:Line added for *@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr on Tue Mar 28 16: 21:56 2006 GMT (from [email protected] to expire at Tue Mar 28 22:21:56 2006 GMT: Open Proxy found on your host. Please visit www.blitze d.org/proxy?ip=82.122.204.148 for more information.) [Mar 28 16:21:57 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm :*** Notice -- Client exiting at fr2.irc.delgurth.com: Titiz (VilainZ@AMarseille-151-1-1 3-148.w82-122.abo.wanadoo.fr) [User has been banned from Hyperiums (Open Proxy found on your host. Please visit www.blitzed.org/proxy?ip=82.122.204.148 for m ore information.)] [82.122.204.148] Then I removed the gline: [Mar 28 16:22:18 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm :[email protected] removed G:Line *@AMarseille-151-1-13-148.w82-122.abo.wanadoo.fr (set at Tue Mar 28 16:21:56 2006 - reason: Open Proxy found on your host. Please visit www.blitzed.org/proxy?ip=82.122.204.148 for more information.) [Mar 28 16:24:10 2006] IRC READ -> :nl1.irc.delgurth.com NOTICE bopm :*** Notice -- Client connecting at fr2.irc.delgurth.com: Titiz (VilainZ@AMarseille-151- 1-13-148.w82-122.abo.wanadoo.fr) [82.122.204.148] {0} [Mar 28 16:24:10 2006] IRC REGEX -> Regular expression caught connection notice. Parsing. [Mar 28 16:24:10 2006] IRC REGEX -> Parsed [email protected] [82.122.204.148] from connection notice. [Mar 28 16:24:10 2006] DNSBL -> Passed '148.204.122.82.opm.blitzed.org' to resolver [Mar 28 16:24:10 2006] SCAN -> Passing [email protected] to scanner [default] [Mar 28 16:24:10 2006] DNSBL -> Lookup result for [email protected] (148.204.122.82.opm.blitzed.org) 0.0.0.0 (error: 3) [Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:1080 (SOCKS4) [default] (39 bytes read) [Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:1080 (SOCKS5) [default] (39 bytes read) [Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:23 (WINGATE) [default] (39 bytes read) [Mar 28 16:24:10 2006] SCAN -> Negotiation failed 82.122.204.148:23 (ROUTER) [default] (39 bytes read) [Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:80 (HTTP) [default] (0 bytes read) [Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:8080 (HTTP) [default] (0 bytes read) [Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:3128 (HTTP) [default] (0 bytes read) [Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:6588 (HTTP) [default] (0 bytes read) [Mar 28 16:24:40 2006] SCAN -> Negotiation timed out 82.122.204.148:4480 (HTTP) [default] (0 bytes read) [Mar 28 16:24:40 2006] SCAN -> Scan 82.122.204.148 [default] completed [Mar 28 16:24:40 2006] SCAN -> All tests on [email protected] complete. All I can see here is that bopm received 39 bytes of data the second time, but no longer a positive. > 2) Try to block incoming connections from "external IPs" using firewall He could try blocking incoming connections from the scanner ip-address I guess. > 3) Try to add this CCProxy IP address to "exempt" section in BOPM config That's not going to work, since he's getting a new IP address quite often. @eric No he's not running an ircd, and as I said, trying to connect to his host after he's banned I get: 83.160.25.144 is external user, blocked And this is my list of matching strings, even if he has a ircd, he needs to use the same name for his ircd as I do to make it give a false positive. target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Looking up your hostname..."; target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Found your hostname"; target_string = ":nl1.irc.delgurth.com NOTICE AUTH :*** Found your hostname (cached)"; target_string = "(Throttled: Reconnecting too fast) -Email [email protected] for more information."; Regards, Wessel van Norel