Re: [Full-Disclosure] blocking SkyPE?

From: Alain Fauconnet (alain_at_ait.ac.th)
Date: 01/25/05

  • Next message: Pseudo Nym: "Re: [Full-Disclosure] hushmail.com, is this true?"
    Date: Tue, 25 Jan 2005 19:04:29 +0700
    To: full-disclosure@lists.netsys.com
    
    

    Bryan,

    Thanks for your input.

    On Tue, Jan 25, 2005 at 12:04:45AM -0800, lists-security@nettracers.com wrote:
    > Full-Disclosure aspect: knowing the capabilities and limitations of the
    > various firewalls employed. How policies can be violated without detection.
    > Vendors and open-source community need to push to solve these real world
    > problems.
    >
    > >...but the real question is: can they detect SkyPE specifically?
    >
    > This is from a Fortigate with factory release NIDS, AV and IPS databases -
    > nothing custom - (someone with a checkpoint and others may pipe in here with
    > their capabilities):
    >
    > On Status page:
    > Recent Intrusion Detections
    > Time Src/Dst Service Attack Name
    > 2005-01-24 22:35:16 10.0.0.12 206.14.209.40 http skype
    >
    > Skype In Alert Log:
    > 2005-01-24 22:35:16 log_id=1421051110 type=ips subtype=signature pri=alert
    > vd=root attack_id=109051909 src=10.0.0.12 dst=206.14.209.40 src_port=3743
    > dst_port=80 src_int=port1 dst_int=port2 status=detected proto=6 service=http
    > msg="p2p: skype,[Reference: http://www.fortinet.com/ids/ID109051909]"
    >

    I think that this may trigger on the regular HTTP request that SkyPE
    does at start up (and only then). This checks the SkyPE web site for
    updates. This is also what the available Snort signature trigger on,
    simply because it's the only kind of traffic that has a recognizable
    signature.
    How many hits do you have for a given client IP on this rule? If it's
    really triggering on VoIP traffic, you should get many per second.

    > I am not blocking skype traffic or the kazaa traffic that is detected, but
    > use this info to quantify the use of the network and to throttle bandwidth
    > if needed to maintain QOS for business-critical functions.

    If that's just the version check traffic (and my gut feeling is that
    it is, considering the data you've shown), this is *not* the kind of
    SkyPE traffic you'd want to classify, and your QoS probably doesn't do
    what you think it does (unless it shapes all traffic to/from that
    client's IP)... What do you think?

    [rest deleted - amen to all of this... including the pathetic "security
    advice" of the SkyPE folks]

    Greets,
    _Alain_
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Pseudo Nym: "Re: [Full-Disclosure] hushmail.com, is this true?"

    Relevant Pages

    • Re: OT: What happens after ditching long distance?
      ... I wouldn't do the QoS in the 3346 anyway. ... You don't need the VoIP version unless you wanna ... For long distance, I use Skype, Gizmo5, and several private Asterisk ... cordless phone plugged into the phone port. ...
      (sci.electronics.design)
    • RE: [Full-Disclosure] blocking SkyPE?
      ... This checks the SkyPE web site for updates. ... >also what the available Snort signature trigger on, ... I am getting 3-10 hits per second for any active system running this, ... The plan is to shape the entire users system to throttle to a lower priority ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] blocking SkyPE?
      ... knowing the capabilities and limitations of the ... How policies can be violated without detection. ... Skype In Alert Log: ... for your Skype to be able to connect to the Skype network and will not make ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] blocking SkyPE?
      ... >certain are you that Skype is really something you want to block. ... the issue is the existence of patterns for L7 detection ... dynamically blacklist the target IP would be a track to explore. ... authenticate through any SN (that basically tunnels the authentication ...
      (Full-Disclosure)

  • Quantcast