Jump to content

Peter

Members
  • Posts

    4
  • Joined

  • Last visited

Reputation

0 Neutral

About Peter

Personal Information

  • Homepage
    http://www.ipoque.co.uk
  1. Peter

    Web Filtering

    Yes, you can block P2P & IM and such by the apps default port numbers within a firewall. But, the developers of these apps are deliberately making these apps evasive and sneaky with the intent to go through firewalls. Common techniques to circumvent port blocking is to tunnel P2P & IM data within common ports such as 80 and 25. Who will close port 25 when running a mail server? P2P apps also use encrytion to make identification difficult. Skype is the most evasive and difficult app to stop to date. For example, Skype uses a https request in its preamble on the basis that most firewalls will allow https request. Why should we block Skype some say? Well its an undocumented protocol, closed protocol and can consume lots of bandwidth when running as a supernode. Also, the file transfer bit cuts right through most firewalls and therefore is a major security threat. Plus, who really knows apart from Skype development team what the program is really doing? Other techniques include tunneling to external proxies and there are several companies offering a commercial service specifically to evade firewalls and security. Hopster is one service. Preventing P2P and apps that are deliverately evasive is not easy and several P2P apps such as the new version of BitComet openly brag about evading certain expensive brand solutions - Packeteer. Also, as I mentioned in earlier post chat channels are now distributing lists for sharing files via bots. It all makes securing an internet connection interesting and there's always something new to learn.
  2. Peter

    Web Filtering

    Web filtering? . . . you do it because you want to protect pupils/students from unacceptable web content such as pornography? But, pornography and other unacceptable content is now readily available from most P2P networks. Kids can easily run a copy of bitcomet or blubster P2P (executable file) client on their USB sticks and get easy access to content most would find offensive. i.e Ken Bigley video. Xdcc is another example of how kids can easily get access to unacceptable content from the internet - Xdcc utilises IRC with bots to distribute file lists for file sharing. Xdcc is not new but has made a comeback recently, with colleges and unis finding they have hacked servers providing disk space for file sharing by Xdcc. Please keep in mind unacceptable content is not only delivered through http. regards Peter.
  3. For a secure Linux gateway box to scan SMTP mail for SPAM and virus check out http://www.ijs.si/software/amavisd/ regards Peter
  4. For any who have an interest in controlling P2P IM traffic and Skype on their school network - you can find out more about our P2P Filters at our web site http://www.ipoque.co.uk including several High Schools we have worked with and have implemented our P2P Filter. I am more than happy to discuss and demonstrate our solution to interested schools. Apologies for this, but its hard for a small company to get info out to the right people in schools. The ones that understand IT! I am not a salesman but an engineer. If anyone is interested in this subject please contact me. If it's of no interest please disregard this post. No flames please. kind regards Peter
×
×
  • Create New...