Vernon Schryver vjs@calcite.rhyolite.com
Mon Oct 2 14:05:24 UTC 2006

> From: Pavel Urban <pavel.urban@imaginet.cz>
> our firewall guy discovered that dcc server began to try this:

> 150 Opening BINARY mode data connection for '/bin/ls'.

> He says that he never saw this. Is it OK?

The machine hosting z.dcc-servers.net changed abruptly on Friday night.
I suspect your pubic DCC server is trying to contact the new IP address
to fetch copies of the blacklist that all DCC servers use for protection
against bad anonymous clients.  One can see the blacklist at

The script /var/dcc/libexec/fetchblack that a public server should use
to fetch the blacklist tries HTTP before falling back to FTP, but I I
do not yet have HTTP(S) servers running on the new system

I also have not yet sent email announcing the change.  All DCC
server operators, not only public DCC servers, need to change their
firewalls to allow packets from the new address to
their UDP port 6277 to support the server status web page.
The old address was

Vernon Schryver    vjs@rhyolite.com

