Re: ircd on 8080

David Leadbeater <[email protected]> Sat, 21 Jun 2008 16:45:16 +0000
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
Hi Matt,

It's something that has been in the FAQ for awhile, basically as BOPM
just matches on a string returned this will happen, we recommend you
exclude the IRCD itself from scanning. Alternately you can run a
daemon that returns a known string on a known port (e.g. just an echo
command via inetd) and match on that instead.

BOPM was stricter at one point, however some proxies are badly
implemented so it is very liberal in what it accepts as a proxy.

(This issue also isn't helped by the fact the DroneBL does no checking
of submissions to them, so you can get yourself into some trouble if
you connect to a BOPM that is submitting to DroneBL.)

David

On Fri, Jun 20, 2008 at 11:18:14PM +0100, Matt S Trout wrote:
> Due to evil conference wireless with firewalls, I temporarily put my ircd
> listening on 8080 as well as other ports.
> 
> The first time a user on the ircd's server reconnected, the scan detected
> the 8080 ircd listen as an open proxy and promptly klined all the shell
> clients - and itself.
> 
> Is this expected and I just shouldn't do that, or should I go digging to
> try and figure out how it saw the ircd as a proxy? (it's hybrid-7.2.3 with
> a few patches we maintain running as part of irc.perl.org; I don't believe
> the patches are relevant but will happily test without them if that would
> help)
> 
> Basically, am I an idiot and/or should I be debugging this further?
> 
> -- 
>       Matt S Trout       Need help with your Catalyst or DBIx::Class project?
>    Technical Director                    http://www.shadowcat.co.uk/catalyst/
>  Shadowcat Systems Ltd.  Want a managed development or deployment platform?
> http://chainsawblues.vox.com/            http://www.shadowcat.co.uk/servers/