Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
filter msn access
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
tecknojunky
Veteran
Veteran


Joined: 19 Oct 2002
Posts: 1937
Location: Montréal

PostPosted: Sun May 08, 2005 7:35 am    Post subject: filter msn access Reply with quote

I know you can connect to MSN through a SOCKS proxy (what is it).

I was wondering if it was possible to filter MSN traffic to shake out malware. I'd mostly like to be able to run a virusscan of files that would be transferd, stuff like that.

How should I go about? I have a squid proxy for http caching, is it good enough?
_________________
(7 of 9) Installing star-trek/species-8.4.7.2::talax.
Back to top
View user's profile Send private message
BlackB1rd
Tux's lil' helper
Tux's lil' helper


Joined: 13 Aug 2003
Posts: 131
Location: /Europe/Netherlands/Haarlem

PostPosted: Sun May 08, 2005 6:32 pm    Post subject: Reply with quote

Force your msn to use a proxy server (squid as you mentioned is already running, so this should be easy). Then, install something like dansguardian with virus support. This way all msn traffic (since it will pass though the proxy) get scanned for virusses. Though, i'm not sure if direct file-transfer can work this way.

I am currently using the hard masked dansguardian-dgav package, which should work fine for you (it's hard masked because of bug #89948) . But i only use it for browsing, not msn. So again, this might work but i don't know much about the way msn handles it's traffic.
Back to top
View user's profile Send private message
tecknojunky
Veteran
Veteran


Joined: 19 Oct 2002
Posts: 1937
Location: Montréal

PostPosted: Mon May 09, 2005 3:00 pm    Post subject: Reply with quote

I also have f-prot on the server for mail virii scanning, I don't know if I can integrate that instead. I'm not sure I want/can to scan for file transfers. I think it has its own protocol since some negociations takes place directly between the two boxes. You kind of realize that when you try to transfer stuff between two NATed machines. It does not work because one client send a NAT IP address, and the other can't route packets to that on the public network. So I don't think it's possible to scan files transfer upstream on a proxy, unless it is the proxxy that negociate and receive the file transfer, and I don't think squid does that, but maybe others do?

I'm ot using Windows anymore myself, but some users inside the lan do, and some trojan made is way thrue MSN. So I was brain storming ideas to see if I can prevent that in any way.

Thanks for the tip. I will check out dansguardian.
_________________
(7 of 9) Installing star-trek/species-8.4.7.2::talax.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum