Blocking Morpheus

From: Jamie (darkshad@subdimension.com)
Date: 10/29/02


From: "Jamie" <darkshad@subdimension.com>
Date: Mon, 28 Oct 2002 23:17:08 GMT

Your software is a good idea but.. a couple of things

1. I need it to be able to run on the server side and
the server here is linux.

2.

With Morpheus and it client side. There is no central
server in Morpheus 2.0 So what it does is each time it
connects directly to each client. Which makes it virtually impossible
to block. I am seeing that now in Morpheus 2.0 It also appears
to be using random ports to connect in. I have the ports
that Morpheus uses blocked right now. But yet If I install
Morpheus I can still connect. The people who made
Morpheus has drasticly reworked Morpheus in the
version 2.0 The ports I have blocked at 6346 - 6348

As I stated before I have these ports blocked but yet Morpheus
is still some how able to connect. It is seeking out alternate
ports and connecting on them. And the ports it is using to connect
appear to be quite random. What I can see it doing is it is connecting
another client on another port and pulling a list of active servers
from that other client. That appears to be how Morpheus 2.0 works.
You connect to another client and it will send you the list of active servers
that the other client knows about. Also the problem is too that every time
some one has your IP cached in the list of servers that each time
they startup Morpheus it sends a packet of info to that IP to see if it can
connect to the client. If the client isn't active then it will remove you from
the list. So if a lot of people have your IP cached in thier server list you
can get bombarded with unwanted traffic. And I really can't see a way
to block this because it is all client side. Sure I can block 1 or two
IPs but it just connects to another one. And it is randomly jumping
ports to other ports when it doesn't have access to port 6346 - 6348

I have those ports blocked but yet as a test I startup Morpheus here and
it is still connecting.

If you go in under edit then down to options as well and then click on
connections you can watch it try and connect to the various clients.
Like I said I can block those few clients but it will just find more
and connect to those.

I even tried something different as well I tried blocking a few of
of the Morpheus IP blocks as well using IP tables on
my Slackware 8 gateway/firewall.

${IPTABLES} -A FORWARD -d 206.142.53.0/24 -j REJECT
${IPTABLES} -A FORWARD -d 209.61.128.0/18 -j REJECT
${IPTABLES} -A FORWARD -d 140.99.0.0/16 -j REJECT

And also as I stated before I have the ports from 6346 - 6348
blocked as well nothing seems to be working.

So I don't see how your blocking Morpheus 2.0 clients.
The Older clients were easier to block but I believe the people
at Music City has specifically designed thier software this way
so that it can not be blocked.

And this is totally unacceptable for Morpheus to do.

Jamie

--
For newsgroups and email this message is the property of the sender.
NO portion of this message may be copied or reposted without my
written consent. The message may not be altered in any way with
out written permission. Copyright © 2002 by Jamie

Return-Path: <WarrenSoftware@plevna.f9.co.uk> Received: from localhost (darkshad@localhost [127.0.0.1]) by darkshado.dyndns.org (8.12.6/8.12.6) with ESMTP id g9SBLDCK025213 for <darkshad@localhost>; Mon, 28 Oct 2002 06:21:15 -0500 Received: from 192.168.0.1 [192.168.0.1] by localhost with POP3 (fetchmail-5.9.14) for darkshad@localhost (single-drop); Mon, 28 Oct 2002 06:21:15 -0500 (EST) Received: from marstons.services.quay.plus.net ([212.159.14.223]) by mc7-f38.law1.hotmail.com with Microsoft SMTPSVC(5.0.2195.4905); Mon, 28 Oct 2002 03:02:19 -0800 Received: (qmail 7145 invoked by uid 10001); 28 Oct 2002 12:06:44 -0000 Received: from dyn70-37.sftm-212-159.plus.net (HELO tony) (212.159.37.70) by marstons.services.quay.plus.net with SMTP; 28 Oct 2002 12:06:44 -0000 From: "T Warren" <WarrenSoftware@plevna.f9.co.uk> To: <surfer800@hotmail.com> Subject: Blocking Kazaa and other peer-to-peer applications on workstations Date: Mon, 28 Oct 2002 10:02:20 -0000 Message-ID: <000f01c27e69$1bf4f760$46259fd4@tony> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0010_01C27E69.1BF4F760" X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.2616 Importance: Normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 X-OriginalArrivalTime: 28 Oct 2002 11:02:19.0437 (UTC) FILETIME=[7BDE5DD0:01C27E71] X-SpamBouncer: 1.6 beta (10/17/02) X-SBClass: OK X-Folder: Default X-UIDL: RE2!!e_C!!=R1"!`=D"! ----- Original Message ----- From: T Warren To: surfer800@hotmail.com Sent: Monday, October 28, 2002 5:02 AM Subject: Blocking Kazaa and other peer-to-peer applications on workstations

Hi

You may be interested in Warren Software's solution to KaZaa, Morpheus and other peer-to-peer programs. Called TerminatorX it runs invisibly on workstations and matches window titles of currently open windows with a list updated from the server.

The user does not have edit rights to the list server list, wild card list entries are possible and the application is terminated (shut down) when a match is found.

The list update frequency and the period between sweeps through the open windows are both provided in the list on the server.

For more information and to download a free trial, please see http://www.plevna.f9.co.uk/tindex.htm.

If you need any additional information please contact me.

Tony Warren

Warren Software

WarrenSoftware@plevna.f9.co.uk



Relevant Pages

  • RE: serial ports?
    ... including the client file system, smart cards, audio, serial ... ports, printers, and the clipboard. ... terminal services only can redirect the serial ports to the Terminal ... redirected to the Terminal Server. ...
    (microsoft.public.windows.terminal_services)
  • Re: Exchange ports through firewall?
    ... I take there are too many ports to open if we use the full client method? ... in this case if you want to provide clients RPC/MAPI access across a firewall, you can restrict clients and server to a narrower range of ports, or alternatively open a lot more ports on the firewall. ...
    (microsoft.public.exchange.admin)
  • Re: Microsoft FTP and Linksys BEFSR41 (okay, Kerio 2.1.5 also)
    ... configure PASV on your server, and ask people to use PASV ... If the client has a router which isnt well implemented for FTP ... it will drop incoming connections on high ports ...
    (comp.security.firewalls)
  • Re: How to setup Manual printer redirection
    ... The client must be ... > connected to the terminal server during manual redirection. ... Ports for all clients currently connected ...
    (microsoft.public.windows.terminal_services)
  • Re: What doesnt lend itself to OO?
    ... >> proxy and instructs the server to constuct the real object. ... rather than client code. ... If 'clock' is instantiated in the server, ... > for the server interface at the OOA level. ...
    (comp.object)