Saturday, December 02, 2006

New Skype Version is harder to detect and block, So just Uninstall Skype.

Again Skype comes to my aid, The article, VOIP IP Telephony: Why Skype Business version might not Fly! just describes how Skype install behaves on a PC. The sear number of folders were bad enough, now it is revealed that it is even harder to detect skype on a network. Sometimes it is necessary to know what is running on your network. May be one need to provision portion of the network with various data streams based on priority. But looks like with skype it is no no. I want all of it. Welcome to business business world. They may have to give up trying detect and control Skype and just settle to banning or uninstalling rogue users. There are many such resources are emerging. The longstanding Skypekiller (see the link below) and Sophos has a plug in for their anti virus software at no additional cost. So if you have Sophos, it might be the way to go. But if you want to do a domain wide removal, Skypekiller is the way to go.
Sidenote: Do a whois search for skyperkiller, Skype owns most of it!

The stealthiness of skype is getting better according to an article published on CSO site. May be to hide from increasing push by rival ISPs and governments and Many corporates, sensitive of data security, also have an urgent need to filter it.

The article has information from Germany-based iPoque which markets hardware-based systems for detecting and blocking a range of unauthorized software bing used on corporate networks, notorious P2P systems such as BitTorrent, Skype and other nuisances.
“This time we had a hard time to find a pattern and not create false positives [at the same time],” said CEO Klaus Mochalski.. Despite this, the changes from version 2.5 to 3.0 had not been as significant as those from version 2.0 to 2.5, he indicated. In the longer run, it would be difficult for Skype to change so as to hide completely because it always had to release new software that maintained backward compatibility.

But, there have been a number of subtle but important alterations in 3.0, including a change to the way the client opens encrypted UDP channels to other clients, as well as to the packet lengths themselves. Since the software was already extremely hard to detect, and uses an encrypted channel once calls have been started, blocking filters have depended on tracing small but telltale patterns such as this.

The software also appeared to have been overhauled to make it less likely that intrusion prevention systems unable to properly identify Skype would classify its traffic as “bad” by lowering the number of TCP connections the client attempts to open. This would avoid triggering TCP thresholds set on such systems, according to Mochalski.

Links;
VOIP IP Telephony: Why Skype Business version might not Fly!
VOIP IP Telephony: Remove skype, stop skype or detect skype with skypekiller
News source CSO
SkypeKiller free software
iPoque

0 comments:

Blog Widget by LinkWithin