OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: blocking icq & napster
From: Brian Sadler (lyrabasHAL-PC.ORG)
Date: Mon Aug 28 2000 - 22:35:44 CDT


In theory this sounds like it would work but in reality it depends on what
version of ICQ they are using. For example, I am using ICQ2000 behind a
firewall that only has ports 80 & 25 open. The new version of ICQ will search
until it finds an open port and use that port. It works around the firewall.
Currently on port 80. To stop it from doing that would also knock out your
http access port.

> But with ICQ it is possible to block server access, which is port 4000.
> ICQ is unuseable if the client cannot log on.

Sorry, I haven't looked at the napster thing yet.

> Napster however, is more or less unstopable that way. And whats worse,
> Napster uses far more bandwith than icq (Which hardely uses any).
>
> One way I could imagine it done would be by filtering Napster login
> packets out. However I have not seen or done this in praxis.