Notices
Non Scooby Related Anything Non-Scooby related

Any tips on blocking ICQ

Thread Tools
 
Search this Thread
 
Old Dec 13, 2001 | 11:56 AM
  #1  
mega_stream's Avatar
mega_stream
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Question

I've read on phoneboy that ICQ can be tunnelled over http using some program...as far as I can see on the f/wall log this is whats heppening.

Can anyone give me any tips how I can stop this?

Cheers

John
Reply
Old Dec 13, 2001 | 12:01 PM
  #2  
orbv's Avatar
orbv
Scooby Regular
 
Joined: Apr 2001
Posts: 1,103
Likes: 0
From: Hants
Post

Create an outgoing rule to block traffic to the icq servers.
Reply
Old Dec 13, 2001 | 12:03 PM
  #3  
mega_stream's Avatar
mega_stream
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Unhappy

I'm using Raptor

Can't do URL blocking without webnot
Reply
Old Dec 13, 2001 | 12:04 PM
  #4  
Dizzy's Avatar
Dizzy
Scooby Regular
 
Joined: May 2001
Posts: 2,537
Likes: 0
Post

Your not my network admin are you?

if it does do that then its pretty tricky to stop as the port http request reply on is a standard feature. Its been a while since I set up out cisco router.

just looked at the icq settings.. if you just ban the icq.com ip's (login.icq.com = 205.188.179.233) then the http web requests will be banned at the same time.. know its a bit ham fisted but dont know what else 2 suggest.
Reply
Old Dec 13, 2001 | 12:04 PM
  #5  
dsmith's Avatar
dsmith
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

http://www.phoneboy.com/faq/0059.html gives some IP addresses etc to block. (and www.icqproxy.com = 63.218.224.159)

Failing that it may be possible to dig down into FW-1 and write some inspect code to check for not http port 80 traffic but I've personally not done that sort of thing

Juts seen the raptor repsonse so FW-1 not going to be much use

[Edited by dsmith - 12/13/2001 12:06:17 PM]
Reply
Old Dec 13, 2001 | 12:08 PM
  #6  
Dizzy's Avatar
Dizzy
Scooby Regular
 
Joined: May 2001
Posts: 2,537
Likes: 0
Post

doh while typing my suggestion other ppl beat me too it cant belive u can't ban ip's though... seems to be a good firewall (after a brief search on the net)
Reply
Old Dec 13, 2001 | 12:09 PM
  #7  
mega_stream's Avatar
mega_stream
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Post

Emm, I think maybe I can edit the conf file to get Raptor to block url's that way...
My understanding is that raptor out the box can only do http allows, so all other url's other than those specified are dropped.
Reply
Old Dec 13, 2001 | 12:10 PM
  #8  
dsmith's Avatar
dsmith
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

It can block IP addresses though (I'm sure they couldn't call it a F/W otherwise ).
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
bluebullet29
General Technical
9
Oct 5, 2015 02:17 PM
Ganz1983
Subaru
5
Oct 2, 2015 09:22 AM
Wurzel
Computer & Technology Related
10
Sep 28, 2015 12:28 PM
wms-racing
Wanted
0
Sep 28, 2015 10:05 AM




All times are GMT +1. The time now is 11:59 PM.