Snort mailing list archives

Re: Chat/IM


From: Craig Paterson <craigp () tippett com>
Date: Tue, 13 Apr 2004 14:21:17 -0700

Remko Lodder wrote:

Harper, Patrick wrote:

Use a proxy and only allow 80/443 and 21/20 ???


Does anyone have an effective way of blocking chat/IM?
Krisa Rowland ERDC Information Assurance Team


That alone won't do it -- most of the IM systems are smart enough to tunnel on port 80 if they can't get out another way. You'll also need to block the login servers, which is a moving target but (depending on how tight your requirement) does a pretty good job of breaking IM for LAN users without a huge time investment.

Craig.



-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: