RE: Best means to block MSN Messenger, AIM and other chat programs?

From: Bejon Parsinia (bejon@supertel.com)
Date: 02/21/02


From: "Bejon Parsinia" <bejon@supertel.com>
To: "'KEN MORRIS'" <KMORRIS@kpl.org>, <security-basics@securityfocus.com>
Date: Thu, 21 Feb 2002 10:00:46 -0800


I have worked with MSN Messenger issues in the past. The problem with MSN
is that it uses the H.323 protocol for the capabilities of VOIP (netmeeting)
and Video Conferencing (also netmeeting). H.323 uses dynamically assigned
ports that span a great range of UDP ports. Check out this url for
information regarding Microsoft's statement on using Netmeeting with a
firewall:
http://www.microsoft.com/windows/NetMeeting/Corp/reskit/Chapter4/default.asp
. Because Microsoft has intermingled the technologies of netmeeting and MSN
in a tightly woven package, it is almost as if one won't exist without the
other. If I remember correctly, there are as many as 2000 dynamically
assignable UDP ports for use in MSN Messenger (and netmeeting).

If you are in a Win2k/NT environment, I suggest that you restrict individual
users from having administrative rights on their local machines. This will
prevent them from being able to install software. Then, you will have to
remove the unwanted chat applications manually. Thus ends the fix on the
independent machines on your wire.

Then, you may be able to block off all of the UDP ports for incoming and
outgoing traffic, but there is a great chance that these ports are needed
for other applications. Speaking of Netmeeting, there are other ports
listed on the link I provided above that will also need to be restricted. I
suggest you set up deny rules for those ports as well.

Good luck!

Bejon Parsinia

-----Original Message-----
From: KEN MORRIS [mailto:KMORRIS@kpl.org]
Sent: Wednesday, February 20, 2002 8:31 AM
To: security-basics@securityfocus.com
Subject: Best means to block MSN Messenger, AIM and other chat programs?

Hello,
I am using both filtering software and Firewall (GNat Box) to try to
block out the use of several chat programs. On the FW I have blocked
ports:
4000 - ICQ
1863 - MSN Messenger
5050 - AOL and
5190 for Yahoo
After having set up the blocking rule, I then tested MSN Messenger in
the system. Problem being that it was still accessible.
Any suggestions as to how to block the use of the programs at the
firewall would be greatly appreciated.
Thank you
Ken Morris
 
 

 



Relevant Pages

  • RE: Best means to block MSN Messenger, AIM and other chat programs?
    ... This chat programs uses any available ports. ... Best means to block MSN Messenger, AIM and other chat programs? ... I am using both filtering software and Firewall to try to ...
    (Security-Basics)
  • Re: How To Use NetMeeting With Private IPs?
    ... Remote desktop & remote assistance in Windows XP will do this & you can send a request for this through MSN messenger. ... I'm not sure of all the features, but still the problem with NetMeeting & routers is that you can't use it & have security. ... If I sound hostile or arrogant you need to read the following before posting a question "How To Ask Questions The Smart Way" at http://www.catb.org/~esr/faqs/smart-questions.html ...
    (microsoft.public.windowsxp.network_web)
  • RE: Best means to block MSN Messenger, AIM and other chat programs?
    ... You would need to also block TCP 5060-5061 and UDP 5060 if users are using XP. ... I have worked with MSN Messenger issues in the past. ... and Video Conferencing (also netmeeting). ... ports that span a great range of UDP ports. ...
    (Security-Basics)
  • Re: Please help me get Netmeeting to work with MSN Messenger
    ... Msn Messenger at one time supported NetMeeting call ... NetMeeting call initiation support was removed in Msn Messenger a number of ...
    (microsoft.public.internet.netmeeting)
  • Re: What language should I use?
    ... > I want to develop a software like NetMeeting and MSN Messenger. ... sending instant messages back and forth. ... If you mean desktop sharing, that _can_ be done with the ...
    (microsoft.public.win32.programmer.messaging)