Re: exempt functionality

ongeboren <[email protected]> Sat, 6 Jan 2007 13:54:08 +0100
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
Imho, you should be using services and define network wide (i.e. not
local like bopm's) bans there, instead of expecting a bopm to place
this kind of bans. A bopm bot is designed to check for open proxies
rather than "admin decisions". Of course the use of services does not
exclude the use of a dnsbl by those services, in case you indent to
use it also from an info website where you inform your users why
they're not welcome. Just don't mix the 2 things.


On 1/6/07, Konstantinos Tzanidis <[email protected]> wrote:
> Hello all and happy new year,
>
> I would like to ask if there is any thought of adding more flexibility
> for the 'exempt' tag. Here is the problem we face:
>
> We run bopms in our network for some years now and they work like a
> charm. In the past we used only your RBL, while some time ago we
> proceeded in running our own RBL for more flexibility. However some of
> us (especially those who run servers outside Greece which are more
> vulnerable to attacks) kept other RBLs too as an extra measure against
> spam, DDoS etc.
>
> The real problem is that some of the Greek ISPs' dynamic pools, often
> appear blacklisted to those RBLs (especially in spamhaus). However this
> is not always true, as it is a common practice for the Greek ISPs to
> change the IP of their dynamic IP customers once every 24h. So it is
> very easy to find a dynamic IP blacklisted by mistake.
>
> So we want to exempt some masks from the Greek ISPs. However if we do
> this (in the way bopm handles exempts) we will also exempt these masks
> from OUR RBL too (something we don't want to do, as there are also
> 'admin decision' entries there except from normal spammers).
>
> The way we found to overcome this problem, is by running two bopms per
> server: the first has only our rbl with no exempts and the second has
> all the other normal RBLs (blitzed, spamhaus, tor, blah blah) with
> excepts for all the Greek ISPs' dynamic pools (so as to be cought from
> our RBL if it is 'admin decision' or else to be left alone even if any
> of the other RBLs report it blacklisted but it matches a dynamic IP pool
> exempt).
>
> However as this method is not so appropriate, do you have any plans to
> extend exempt's functionality per blacklist in the conf so as not to
> have to run two bopm instances per server?
>
> Thank you very much for listening,
>
> Konstantinos Tzanidis
>
> IRCadmin of phobos.irc.gr,
> cyprus.irc.gr - WiZy @ GRNet
>  http://www.irc.gr


-- 
Evlogi Petrov - ongeboren@UniBG