Re: [Win2k] Stopping sw from phoning home

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 09/11/05

  • Next message: mkmom: "Re: error message when clicking on folders or Internet Explorer"
    Date: Sat, 10 Sep 2005 19:30:51 -0500
    
    

    You can use an ipsec filttering policy that contains a rule that has a
    filter list with those IP addresses and a block filter action. The link
    below may also be of help in that it shows the basics of an ipsec filtering
    policy. --- Steve

    http://www.securityfocus.com/infocus/1559

    "ignisfatuus" <ignisfatuus3267nospam@cox.com> wrote in message
    news:ndKUe.76780$Ji4.64527@fed1read03...
    > Mr. Umbach:
    >
    > The good news is that the sw in question uses 2 very specific IP addresses
    > and ports each time it phones home. The bad news is that the source port
    > is 80. I'm going to mess with IPSEC and see if I can create a policy to
    > block this annoying behavior. I've never done it before but am about to
    > learn. I'm starting here.
    >
    > http://support.microsoft.com/kb/813878#XSLTH4153121121120121120120
    >
    > Any further advise would be appreciated. Thx.
    >
    >
    >
    > Steven L Umbach wrote:
    >> Check all the options on it for configuration to see if you can disable
    >> it from doing so. If that will not work you would need to find what IP
    >> addresses and port/protocols it is using. You could use a packet sniffer,
    >> check your routers logs, use netstat -an while it is actively accessing
    >> the internet, or a tool such as port reporter as shown in the link below.
    >> Once you know that information you could configure an ipsec filtering
    >> policy or your router to stop access. It may be difficult if it uses port
    >> 80 TCP since that is used for your internet access unless it uses the
    >> same IP address all the time in which case you could block access to the
    >> specific IP addresses it uses. A software firewall such as Zone Alarm
    >> could easily stop such activity but you seem to be against using such. If
    >> you can track down the executable that is used for automatic internet
    >> access with something like port reporter you could try to delete the file
    >> [save a copy] or change permissions on the file so that user and system
    >> have full control deny permissions. --- Steve
    >>
    >> http://www.microsoft.com/downloads/details.aspx?FamilyID=69ba779b-bae9-4243-b9d6-63e62b4bcd2e&displaylang=en
    >>
    >> "ignisfatuus" <ignisfatuus3267nospam@cox.com> wrote in message
    >> news:cyFUe.76750$Ji4.10382@fed1read03...
    >>
    >>>Note: I do not want to use a sw firewall to do this.
    >>>
    >>>How do I prevent Musicmatch Juke from phoning home? There must be a way
    >>>to stop the software from phoning home in MS Security settings somewhere.
    >>>I'm just not sure where. IPSEC maybe? Please advise.
    >>>
    >>>I've got a DI-604 router but there doesn't seem to be a way to prevent
    >>>the sw in question from venturing out on the Net w/o permission in those
    >>>settings.
    >>
    >>


  • Next message: mkmom: "Re: error message when clicking on folders or Internet Explorer"

    Relevant Pages

    • Re: To IPSec Packet Filter OR Not To IPSec Packet Filter - that is the question
      ... an IPSec policy that should be sufficiently restrictive for your purposes. ... Client's Source port is ANY ... then how can I create an IPSec filter that blocks all ...
      (microsoft.public.win2000.security)
    • Re: IPSec Policy Doesnt Really Block
      ... basic filters to allow port 80 and port 25 inbound from Any to My IP, ... >I have created ipsec policies that work. ... The I add mirrored permit rules for the exceptions such ... >> Here is a list of IPSECPOL.exe commands I am using to create the policy. ...
      (microsoft.public.win2000.networking)
    • Re: IPSec Policy Doesnt Really Block
      ... basic filters to allow port 80 and port 25 inbound from Any to My IP, ... >I have created ipsec policies that work. ... The I add mirrored permit rules for the exceptions such ... >> Here is a list of IPSECPOL.exe commands I am using to create the policy. ...
      (microsoft.public.win2000.security)
    • RE: Access to well-known ports on Win2K
      ... IPSEc does not provide security at the user level; ... policy - works for all users of the machine; and can allow or block access ... many routes for deployment as you mention: Group Policy; Local Security ... > TCP/IP Filtering does not provide port level security at the ...
      (Focus-Microsoft)
    • Re: ipsecpol on Windows 2000
      ... To use IPSec to port filter a server, you cannot allow any TCP client services ... DNS needs TCP for any responses that won't fit into UDP. ...
      (Focus-Microsoft)