Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 log msn traffic

views
     
debiankl
post Mar 1 2005, 02:12 PM

On my way
Group Icon
Elite
577 posts

Joined: Dec 2004
From: Inside the CPU core stack register SP


Becos MSN used port 80
debiankl
post Mar 1 2005, 05:14 PM

On my way
Group Icon
Elite
577 posts

Joined: Dec 2004
From: Inside the CPU core stack register SP


QUOTE(robertngo @ Mar 1 2005, 04:07 PM)
the firewall only allow direct connection to internet for ssh, telnet and mail, how can msn go to the internet directly using port 80?
*
Wrong info, port for yahoo messenger.

Here are list of ports used by MSN

389 : TCP MSN NetMeeting
522 : TCP MSN NetMeeting
1024 : UDP MSN NetMeeting (ports 1024 - 65535)
1503 : TCP MSN NetMeeting Whitebord and Application Sharing
1720 : TCP MSN NetMeeting
1731 : TCP MSN NetMeeting
1838 : TCP MSN Messenger (Gamevoice)
1863 : TCP/UDP MSN Messenger primary (incoming)
2300 : TCP/UDP MSN Gaming Zone DX (incoming) - ports 2300-2400
2880 : TCP MSN Gaming Zone (ports 2880-29000). Caution: all ports open will become a security problem!
3389 : TCP MSN/Microsoft RDP (Remote Desktop Protocol) for Remote Assistance
5004 : UDP MSN Messenger, ports 5004-65535. Used for AUDIO and VIDEO. Caution: securty risc! Do not open ALL these ports!
5004 : UDP MSN messenger (dynamically uses a port in this range 5004 - 65535 - requires uPNP in your NAT router and/or firewall). Used for AUDIO and VIDEO. See Microsoft website for details.
5190 : UDP MSN Messenger (incoming)
6667 : TCP MSN Gaming Zone (incoming)
6891 : TCP MSN Messenger Filetransfer (incoming) - ports 6891 - 6900, one port per file transfer
6901 : TCP/UDP MSN Messenger Voice Telephony (incoming)
28800 : TCP MSN Gaming Zone (incoming) - ports 28800 to 29000
47624 : TCP MSN Gaming Zone DX (incoming)

debiankl
post Mar 1 2005, 11:05 PM

On my way
Group Icon
Elite
577 posts

Joined: Dec 2004
From: Inside the CPU core stack register SP


QUOTE(92grad @ Mar 1 2005, 08:32 PM)
If I am not mistaken, some of the Messenger clients can tunnel through your legitimate connections such as email, web etc.
*
Which mean you cannot block port 80 if MSN uses http tunneling, but you can configure squid's ACL block msn domains
debiankl
post Mar 2 2005, 03:45 PM

On my way
Group Icon
Elite
577 posts

Joined: Dec 2004
From: Inside the CPU core stack register SP


QUOTE(robertngo @ Mar 2 2005, 01:02 PM)
is there anyway to know who they have been chatting with on msn, i dont need to know what they are talking about, just the lenght of the converstation.
*
I can't remember of such tools avaliable yet but this is an interesting report for managment.

Otherwise writing a Perl or Python script grep all packets going to MSN domain and source IP address and parse to RRDtool that output results in graphical format.



 

Change to:
| Lo-Fi Version
0.0124sec    1.28    6 queries    GZIP Disabled
Time is now: 23rd December 2025 - 12:49 PM