Blocking Instant Messengers?
Michael Mattes asks: "I have been looking for a set of ports/subnets to block in order to disable instant messengers behind my firewall. While MSN is easy to block, ICQ is a little more difficult and it seems as though Yahoo Messenger is designed to do everything possible to not be blocked. I have been reading more and more articles showing companies choosing to block these tools. It seems irresponsible of Yahoo to leave, what appears to me, no choice but to block their entire domain in this situation. Any help would be appreciated."
At our office, we just started sniffing packets until we caught people trolling for sex partners in chat rooms. Slip a few transcripts out to your friends in the office, and they'll whip through the rumor mill in no time. It'll only be a matter of days before nobody will be dumb enough to IM anybody at all, knowing that someone could be listening in.
What's your damage, Heather?
If you can define a snort rule that would pick up some tell-tale of a yahoo IM message, you could then have an 'active response' that would send a tcp reset to each end of the connection spoofed to be from the remote end. This is also effective for blocking gnutella traffic.
Eventually people will give up trying to use yahoo's messenger and switch to something more subversive. when will an icmp-echo reply based IM service get started? That's what the world _really_ needs.
"But actually trying to use m4 as a general-purpose langage would be deeply perverse" --ESR
Good idea, and while you're at it, you can track those who use Yahoo and insert purgatives into their coffee, while inserting D-Lysergic Acid Diethylamide into coffee of people who didn't use Yahoo in a given day. When the users will find a subconcious correlation with their usage of Yahoo and their happiness, the usage will drop accordingly. This is what we, network administrators, call “conditioning.”
root@aio:~# nmap -sX -iR -p1- # Ho, ho, ho! Merry Xmas, everyone!
Yeah, and while we're at it, I think its about time we abolish any and all bathroom breaks from the office! I mean, think about it, taking a 5 minute shit is tantamount to stealing from the company!
There's no excuse for not using the washroom before you go to work, and no excuse for not using a catheter while you're at work. Your bodily functions are your own personal problem and if you can't control them, or at least stop them from interfering with work, you need to be replaced with a robot that doesn't suffer from these setbacks.
(Yup, I'm being sarcastic, and quite frankly, if you told be I couldn't check my email at work. even if you were my boss, I'd tell you to fuck off and tell you that if you won't let me do it, I'm finding another job before you fire me. Even working as a fast food restaurant manager provides more liberties than what you describe. Can you even use the phone to call your wife if she's in the hospital with pneumonia? Or is that a firable offense too?)