Posts: 9
Joined: 21.Apr.2005
From: UK
Status: offline
Skype is turning out to be a administration nightmare, much in the same as SPYNOT and other programs. After drinking half a coffee plantation and a couple of sleepness nights and hot dates with Ethereal and ISA (i know i know.. a stud, 2 on the go at once) Here are my findings.
This document above contains infomation about the gubbins of skype and how to works, makes sleepy bed time reading. it seems that skype uses UDP first to connect then TCP:80 if no luck there TCP:443 ssl tunnel.
I ethereal cap'ed the connection taking place and the only thing i can find is a HTTP: CONNECT Method to a random IP address each time, so blocking the IP address is out of the question as there are 1000's of them. With CONNECT blocked in the ISA method filters, users are then unable to browse any SSL sites as we use an upstream 8080 proxy to our ISP.
I am stuck, skype are not intrested in responding to my emails or calls... someone must be having the same issue. working with children 3000 of them in fact this is potnetialy a very sensitive issue, as they are currently able to talk to anyone accross the internet...
Posts: 9
Joined: 21.Apr.2005
From: UK
Status: offline
Posting a link to the search option wasn't very helpfull, also blocking the skype authtication servers no longer works.
The reason for this i believe tis the way that the skype client authenticates, there did used to be a central auth cluster of some description, but now it uses a P2P type authentication service, which only needs the skype client to be able to access one of the super-nodes.
I read in a previous post that blocking SSL is good practice and this is something that we are planning todo, firstly i need to sell it to the powers to be.