View Single Post
  #1 (permalink)  
Old 12-08-2004, 01:56 AM
Eli_ch Eli_ch is offline
Registered User
 
Join Date: Aug 2003
Location: Switzerland
Posts: 17
Eli_ch
Question SORBS Listing: Reason = Entropy Chat?!

hello,

i have a problem with one from our servers. we are listed since more than one week in the sorbs (http://www.dnsbl.sorbs.net/) list. firstly i thought, one of our customer has send out some spam...but badly we never get a message from sorbs on our abuse contact.

so i mailed the isp support of sorbs and became the following answer:
Code:
The problem is an EntropyChat server....

Trying 217.26.52.31...
Connected to 217.26.52.31.
Escape character is '^]'.
GET /alya.cgi HTTP/1.0

HTTP/1.0 200 OK
Server: EntropyChat 0.2.5
Cache-Control: no-cache
X-Author: bdraco@darkorb.net
Pragma: no-cache
Content-type: text/html

<html><!--#lobby - Guest6573--><frameset rows="*,90" border=0
                        frameborder=0><frameset border=0 frameborder=0
                           cols="*,150"><frame
src="chat?sessionid=4n6hzd_u1xUuuI9AU8dASWh9IuOO98JW5_b03TLxEh7wuptgkeC0WNSzQmKmGsQHTP90kF3ttAE"
border=0
                           frameborder=0><frame border=0 frameborder=0
                          
src="names?sessionid=4n6hzd_u1xUuuI9AU8dASWh9IuOO98JW5_b03TLxEh7wuptgkeC0WNSzQmKmGsQHTP90kF3ttAE"></frameset><frame
                          
src="talk?sessionid=4n6hzd_u1xUuuI9AU8dASWh9IuOO98JW5_b03TLxEh7wuptgkeC0WNSzQmKmGsQHTP90kF3ttAE"
border=0 frameborder=0></frameset></html>
Connection closed by foreign host.

This is non RFC complient.
so i wrote them back, that entropy chat is running on port 2084 as a standard of cpanel hosting software and if he listed us in sorbs they have to list thousands of other hosts who use cpanel because they are also not rfc complient.


this morning i get another answer from sorbs:
Code:
We have had a few listings - our stance is we will list hosts that
trigger our tests if they are RFC non-complient.  So far this stance has
had a few people complain to the EntropyChat writers and they haven't
complained to us since, so we have to assume they have some sort of fix.

Personally I think the response should be either:

HTTP/1.0 404 Not Found

or 

HTTP/1.0 302 Moved permanently

or even

HTTP/1.0 401 Authorization Required

In all cases there is nothing wrong with returning the login page or the
start page as the content - the important thing is the status code is
correct - it indicates that /alya.cgi doesn't exist there.
is this problem known or are there other isps who has the same problem with sorbs like this?

thanks for some answers and greets

eli
Reply With Quote