Discussion:
bopm not connecting/scanning correctly
Brent Lopez
2009-07-17 07:43:28 UTC
Permalink
[Jul 17 07:16:30 2009] COMMAND -> Parsing command (ProxyMon check
71.227.143.168 extra) from r00tdigger [#opers]
[Jul 17 07:16:30 2009] COMMAND -> parsed [check] [71.227.143.168 extra]
[Jul 17 07:16:30 2009] DNSBL -> Passed
'168.143.227.71.dnsbl.dronebl.org' to resolver
[Jul 17 07:16:30 2009] DNSBL -> Passed '168.143.227.71.rbl.efnet.org'
to resolver
[Jul 17 07:16:30 2009] SCAN -> Passing 71.227.143.168 to scanner
[extra] (MANUAL SCAN)
[Jul 17 07:16:30 2009] DNSBL -> Lookup result for (null)!(null)@(null)
(168.143.227.71.dnsbl.dronebl.org) 0.0.0.0 (error: 3)
[Jul 17 07:16:30 2009] DNSBL -> Lookup result for (null)!(null)@(null)
(168.143.227.71.rbl.efnet.org) 0.0.0.0 (error: 3)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:1181 (WINGATE) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out 71.227.143.168:81
(HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8000 (HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8001 (HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8081 (HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:5748 (HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:443 (HTTP) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out 71.227.143.168:81
(HTTPPOST) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:6588 (HTTPPOST) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8000 (HTTPPOST) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8001 (HTTPPOST) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:8081 (HTTPPOST) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:1978 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:10001 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:30021 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:30022 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:38994 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:15859 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:1027 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:2425 (SOCKS5) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:559 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:29992 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:38884 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:18844 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:17771 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:31121 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out
71.227.143.168:1182 (SOCKS4) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Negotiation timed out 71.227.143.168:23
(ROUTER) [extra] (0 bytes read)
[Jul 17 07:17:00 2009] SCAN -> Scan 71.227.143.168 [extra] completed



it does the same for "default"
David Leadbeater
2009-07-20 17:41:56 UTC
Permalink
Post by Brent Lopez
[Jul 17 07:16:30 2009] COMMAND -> Parsing command (ProxyMon check
71.227.143.168 extra) from r00tdigger [#opers]
[snip]

It would be useful if you gave a little more information..

- Was this an open proxy at the time?
- If so, which port would you expect it to be open on?
- Do you have that port configured to scan for the correct protocol?

The negotation timed out and error from the DNSBL lookup are expected,
as this simply means it didn't find anything..

-dg

Loading...