Snort mailing list archives

Re: Yahoo Instant Messenger


From: Ravi <ravivsn () roc co in>
Date: Mon, 19 Jan 2004 14:38:32 +0530

Hi Biswas,
There is more than that.
Yahoo! Messenger works on ports: 20,23,25,80,119,5050. Based on the Yahoo server IPs, we may succeed in blocking connections. That would effect port 80 traffic too. I dont know whether there is a snort signrature to stop Yahoo!Messenger traffic.
Yahoo Server domain names:

   * scs.msg.yahoo.com
   * scsa.msg.yahoo.com
   * scsb.msg.yahoo.com
   * scsc.msg.yahoo.com

For more info visit this link:

http://help.yahoo.com/help/us/mesg/twin/twin-36.html

-Ravi




Biswas, Proneet wrote:

Traffic on potr 5050 should be yahoo messenger traffic.

    -----Original Message-----
    *From:* Michael Little [mailto:MLittle () bocaresort com]
    *Sent:* Sunday, January 18, 2004 10:57 PM
    *To:* snort-users () lists sourceforge net
    *Subject:* [Snort-users] Yahoo Instant Messenger

    I see in the current chat rules that there are rules to detect
    MSN, AOL, and ICQ. Does any one have a rule or know how to detect
    Yahoo instant messenger. I would like to block all instant
    messenger traffic in my network.

    Thanks,
    Mike Little
    Director of Network Services.





-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: