Re: [fw-wiz] Port numbers for Peer to Peer file sharing apps.

From: Eric Vyncke (evyncke@cisco.com)
Date: 11/22/02


To: Mikael Olsson <mikael.olsson@clavister.com>
From: Eric Vyncke <evyncke@cisco.com>
Date: Fri Nov 22 08:34:01 2002

If you are concerned only by the waste of bandwidth, you may want to:
- block all incoming TCP connections but the really needed ones
- instead of blocking port 1214, ... you may want to use QoS feature on router or ... to limit the bandwidth to a few kbps

The reason behind the second point is to fool the cluefull students: some traffic is going anyway, so, they will not try other ports but the default.

NB: I admit that this is not an absolute design ;-)

-eric

At 10:58 21/11/2002 +0100, Mikael Olsson wrote:

>Mark Whobrey wrote:
>>
>> I am trying to find a list of ports used by the most common p2p file
>> sharing applications.
>
>There's a fairly comprehensive list at:
>http://www.practicallynetworked.com/sharing/app_port_list.htm
>
>But, as someone else said, there's also several that will use
>ports like 80, 21, 25, and some systems that allow changing the
>port numbers manually, which I have seen heaps of clued users
>doing (and, of course, the not-so-clued users doing a couple of
>days/weeks later).
>
>This all makes me want to start my "don't do app-specific shaping
>on public networks" rant again, but I won't. I'll just point you
>at my previous rant:
>
>http://marc.theaimsgroup.com/?l=firewall-wizards&m=103652075227472&w=2
>http://marc.theaimsgroup.com/?l=firewall-wizards&m=103659628332470&w=2
>
>
>--
>Mikael Olsson, Clavister AB
>Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
>Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05
>Fax: +46 (0)660 122 50 WWW: http://www.clavister.com
>_______________________________________________
>firewall-wizards mailing list
>firewall-wizards@honor.icsalabs.com
>http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] Port numbers for Peer to Peer file sharing apps.
    ... > I am trying to find a list of ports used by the most common p2p file ... > sharing applications. ... which I have seen heaps of clued users ... on public networks" rant again, ...
    (Firewall-Wizards)
  • Re: automake, autoconf compiling
    ... scripts are indeed very platform independent. ... > reason why the FreeBSD ports infrastructure needs to play so many ... the reason the Ports go through all the hoops you see is that they ... One other reason is, of course, the fact that the autotools have changed ...
    (freebsd-newbies)
  • Re: automake, autoconf compiling
    ... scripts are indeed very platform independent. ... > reason why the FreeBSD ports infrastructure needs to play so many ... the reason the Ports go through all the hoops you see is that they ... One other reason is, of course, the fact that the autotools have changed ...
    (freebsd-questions)
  • Re: Clever Firewall Rules, Second Edition
    ... >TCP connect scan doesn't see which ports of mine are open (yes, ... vulnerable to slow scanning (such in large, widespread, interleaved ... Which is the main reason I'd recommend *against* the rules... ... >ban everybody who floods me with SYN packets, ...
    (Focus-Linux)
  • Re: Strange attack question - seems udp
    ... Thanks for explainning the reason for udp ports not appearing in the ... Well the Cisco 3750 is the gateway for my clients and not the ... >>that the length of the packets is always 1500. ...
    (Incidents)