Re: Best means to block MSN Messenger, AIM and other chat programs?

From: ktabic (lists@realitysuxs.co.uk)
Date: 02/21/02


Date: Thu, 21 Feb 2002 20:25:34 +0000
To: security-basics@securityfocus.com
From: ktabic <lists@realitysuxs.co.uk>

TBH, you don't really have that much of a chance blocking these programs by
port, as three of them (I haven't used Yahoo) are perfectly capable of
going though other ports, aside from the default port numbers (I have seen
AIM using port 53 and port 80 to make it's connection)
You would probably have more luck at blocking the addresses the programs
connect to, preferably by name, although IP address would work to.
(Although, IIRC, the IP addresses AOL assigns to their logon server change
regularly, so nmae is better)
HtH
ktabic

At 11:31 20/02/2002 -0500, you wrote:
>Hello,
>I am using both filtering software and Firewall (GNat Box) to try to
>block out the use of several chat programs. On the FW I have blocked
>ports:
>4000 - ICQ
>1863 - MSN Messenger
>5050 - AOL and
>5190 for Yahoo
>After having set up the blocking rule, I then tested MSN Messenger in
>the system. Problem being that it was still accessible.
>Any suggestions as to how to block the use of the programs at the
>firewall would be greatly appreciated.

-- 
Don't even go there



Relevant Pages

  • Re: How do I block just one port from being listened to on my server
    ... Well I looked through ALL my logs; ... Well I'll be testing that Firewall out that you gave the link to. ... I just don't want it blocking everything by ... Blocking one port isn't the answer. ...
    (microsoft.public.security)
  • Re: New install of FC6, httpd wont start at boot
    ... blocking (and yes, they silently block port 80), set that port into ... I dislike arbitrary port blocking. ... and I've got to work out what voltage bulbs are used ... soap, ballot, jury, and ammo. ...
    (Fedora)
  • Re: New install of FC6, httpd wont start at boot
    ... blocking (and yes, they silently block port 80), set that port into ... I dislike arbitrary port blocking. ... had one time base corrector, which had a dud memory board, but actually ... and I've got to work out what voltage bulbs are used ...
    (Fedora)
  • Re: Please help...
    ... you may be able to filter via the application name. ... Otherwise Yahoo messenger normally uses 5050 TCP(peer-to-server dest. ... and 5105 TCP(peer-to-peer listening port) and MSN Messenger 1863 ...
    (comp.security.firewalls)
  • Re: How do I block just one port from being listened to on my server
    ... Blocking one port isn't the answer. ... Blocking these with TCP/IP filtering or IPSec ... Those people who complain about a firewall blocking their chat would have ...
    (microsoft.public.security)