Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Instant messaging?

  1. #1
    Senior Member
    Join Date
    May 2004
    Posts
    140

    Instant messaging?

    HOw would I go about stopping poeple on the network from using an instant chat? AIM, MSN, Yahoo ...
    Should I block the "normal" ports they use? will that keep the avg person from using it?
    any other options?
    Romans 7:14-20
    14 We know that the law is spiritual; but I am unspiritual, sold as a slave to sin. 15 I do not understand what I do. For what I want to do I do not do, but what I hate I do. 16 And if I do what I do not want to do, I agree that the law is good. 17 As it is, it is no longer I myself who do it, but it is sin living in me. 18 I know that nothing good lives in me, that is, in my sinful nature. For I have the desire to do what is good, but I cannot carry it out.

  2. #2
    Senior Member
    Join Date
    Mar 2004
    Location
    Colorado
    Posts
    421
    1st, do you have a policy in place that can be enforced?

    You can block the ports but this can break browsing depending on the port used.

    Some newer firewalls are application aware and can ID messenger traffic and block it but
    I have only seen a few with this support.

  3. #3
    Senior Member
    Join Date
    May 2004
    Posts
    140
    Yes, we have a active policy in place.
    We use the PIX firewall. I was thought it might break browsing cause dont most chats use typical port 80? or 443?
    Romans 7:14-20
    14 We know that the law is spiritual; but I am unspiritual, sold as a slave to sin. 15 I do not understand what I do. For what I want to do I do not do, but what I hate I do. 16 And if I do what I do not want to do, I agree that the law is good. 17 As it is, it is no longer I myself who do it, but it is sin living in me. 18 I know that nothing good lives in me, that is, in my sinful nature. For I have the desire to do what is good, but I cannot carry it out.

  4. #4
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    We are currently dealing with this problem too. Blocking the common port will provide some help, however some of the more popular IM clients will allow for the traffic to flow on port 80. We have set-up blocking to the sites where you can download the client(s).

    e.g.

    http://messenger.yahoo.com/

    We also have a snort rules in place to detect this traffic.

    alert tcp $EXTERNAL_NET 5050 -> $HOME_NET any (msg:"CHAT Yahoo IM successful chat join"; flow:from_server,established; content:"YMSG"; depth:4; nocase; content:"|00 98|"; depth:2; offset:10; classtype:policy-violation; sid:2458; rev:3;)

    alert tcp $HOME_NET any -> $AIM_SERVERS any (msg:"CHAT AIM login"; flow:to_server,established; content:"*|01|"; depth:2; classtype:policy-violation; sid:1631; rev:6;)

    alert tcp $HOME_NET any -> $EXTERNAL_NET 1863 (msg:"CHAT MSN login attempt"; flow:to_server,established; content:"USR "; depth:4; nocase; content:" TWN "; distance:1; nocase; classtype:policy-violation; sid:1991; rev:1;)

    Cheers:
    DjM

  5. #5
    Senior Member
    Join Date
    May 2004
    Posts
    140
    We do not have any IDS in place. We are working on it now. It shoudl be implemented by the end of the yeah. we cannot use a "free" software because of our audit compliance.
    Romans 7:14-20
    14 We know that the law is spiritual; but I am unspiritual, sold as a slave to sin. 15 I do not understand what I do. For what I want to do I do not do, but what I hate I do. 16 And if I do what I do not want to do, I agree that the law is good. 17 As it is, it is no longer I myself who do it, but it is sin living in me. 18 I know that nothing good lives in me, that is, in my sinful nature. For I have the desire to do what is good, but I cannot carry it out.

  6. #6
    BANNED
    Join Date
    Nov 2003
    Location
    San Diego
    Posts
    724
    I don't know if this is feasible? Can you use something like this?
    http://www.websense.com/?Display=IM
    When death sleeps it dreams of you...

  7. #7
    Senior Member
    Join Date
    Mar 2004
    Location
    Colorado
    Posts
    421
    Originally posted here by muert0
    I don't know if this is feasible? Can you use something like this?
    http://www.websense.com/?Display=IM
    Websense and similar solutions can work.
    Often they are very very expensive.

  8. #8
    BANNED
    Join Date
    Nov 2003
    Location
    San Diego
    Posts
    724
    But if things like this start working wouldn't it be worth it?
    http://www.pcworld.com/news/article/0,aid,117998,00.asp
    When death sleeps it dreams of you...

  9. #9
    Senior Member
    Join Date
    May 2004
    Posts
    140
    We have websense...I just dont knwo much about it...I have only been here 6 months and havent had time to look too much into that but i was under the impression it only stops web address access. I know we dont have the Desktop side and that is prolly what blocks IM...
    Romans 7:14-20
    14 We know that the law is spiritual; but I am unspiritual, sold as a slave to sin. 15 I do not understand what I do. For what I want to do I do not do, but what I hate I do. 16 And if I do what I do not want to do, I agree that the law is good. 17 As it is, it is no longer I myself who do it, but it is sin living in me. 18 I know that nothing good lives in me, that is, in my sinful nature. For I have the desire to do what is good, but I cannot carry it out.

  10. #10
    BANNED
    Join Date
    Nov 2003
    Location
    San Diego
    Posts
    724
    If you have websnese enterprise I just finished reading the white paper and it should be builtin so it should tell you how to configure it in the manual.

    Edit: nevermind I found this:
    http://www.websense.com/support/tuto...eCPMPolicy.php

    And here's a list of their other tut's:
    http://www.websense.com/support/tutorials/
    When death sleeps it dreams of you...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •