Firewall Wizards mailing list archives

httport 3snf


From: "Robert E. Martin" <rmartin () fishburne org>
Date: Mon, 21 Oct 2002 09:56:36 -0400

Hi there.
We run Redhat 6.0 with ipchains and have been able to block AIM and others with this system quite effectively, however, our students here have discovered HTTport 3.snf to bypass our proxy server using a SSL connection. Is there a way to stop this without bringing the rest of the newtork to it's knees? I have been unable to sniff the packets successfully enough to find out what ip address the host ssl server is, but I am able to launch the program on my local machine, sniff the packets and see that the first thing that happens is a DNS Request. Can I block DNS requests for a specifid url, ipaddress or other entry via IPCHAINS?

Thanks for your time.

--
Robert E Martin
IT Manager
Fishburne Military School
rmartin () fishburne org
540.946.7726


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: