philippeliso
(usa Ubuntu)
Enviado em 25/03/2011 - 09:17h
Bom galera...
Aqui na empresa onde trabalho, até mais ou menos 1 mes e meio, eu conseguia bloquear o MSN do site do Hotmail....porem de uns dias pra ca descobri que estão acessando via HTTPS....
possuo Squid e iptables, o software do windows live eu consigo bloquear tranquilo, e a porta 80 tb....o problema q estão digitando
https://mail.live.com ou
https://login.live.com e conseguem entrar.....tentei diversas regras inclusive bloquear acessoo total aos Hosts citados e nada, o site apenas demora para entrar mais entra...
ja procurei todos os sites e bloqueei-os os que o windows live usa para conexão, não sei mais o que tentar.....
como tao usando HTTPS o squid nao gerencia, pois se eu colocar o Squid pra gerenciar a porta 443, um monte de site não vai entrar, trazendo mais dor de cabeça ainda...
por isso precisava bloquear pelo firewall mesmo...
segue a config do meu firewall....
......
iptables -A INPUT -s 192.168.0.130 -d mail.live.com -p tcp --syn -j DROP
iptables -A INPUT -s 192.168.0.130 -d login.live.com -p tcp --syn -j DROP
iptables -A INPUT -s 192.168.0.35 -d mail.live.com -p tcp --syn -j DROP
iptables -A INPUT -s 192.168.0.35 -d login.live.com -p tcp --syn -j DROP
iptables -A INPUT -s 192.168.0.35 -d fss.live.com -p tcp --syn -j DROP
iptables -A FORWARD -s 192.168.0.35 -d hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d orkut.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d orkut.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.orkut.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.orkut.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d facebook.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d facebook.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.facebook.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.facebook.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d twitter.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d twitter.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.twitter.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.twitter.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d meebo.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d meebo.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.meebo.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.meebo.com -p tcp --dport 443 -j DROP
iptables -A OUTPUT -s 192.168.0.35 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d login.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d login.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d fss.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d fss.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d
www.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d
www.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d login.live.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d login.live.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d accountservices.msn.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d accountservices.msn.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d accountservices.passport.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d accountservices.passport.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d secure.shared.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d secure.shared.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d signup.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d signup.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d security.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d security.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d extended-validation-ssl.verisign.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d extended-validation-ssl.verisign.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d secure.wlxrs.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d secure.wlxrs.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d rsi.hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d rsi.hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d ows.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d ows.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d config.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d config.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.35 -d co121ds.col121.mail.services.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.35 -d co121ds.col121.mail.services.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d 65.54.165.179 -j REJECT
iptables -A FORWARD -s 192.168.0.130 -d 64.4.56.215 -j REJECT
##
iptables -A FORWARD -s 192.168.0.130 -d 65.54.165.179 -j REJECT
iptables -A FORWARD -s 192.168.0.130 -d 64.4.56.215 -j REJECT
iptables -A FORWARD -s 192.168.0.130 -d co121ds.col121.mail.services.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d co121ds.col121.mail.services.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d orkut.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d orkut.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.orkut.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.orkut.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d facebook.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d facebook.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.facebook.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.facebook.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d twitter.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d twitter.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.twitter.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.twitter.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d meebo.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d meebo.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.meebo.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.meebo.com -p tcp --dport 443 -j DROP
iptables -A OUTPUT -s 192.168.0.130 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d mail.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d login.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d login.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d fss.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d fss.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d
www.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d
www.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d login.live.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d login.live.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d accountservices.msn.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d accountservices.msn.com.nsatc.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d accountservices.passport.net -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d accountservices.passport.net -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d secure.shared.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d secure.shared.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d signup.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d signup.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d security.live.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d security.live.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d extended-validation-ssl.verisign.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d extended-validation-ssl.verisign.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d secure.wlxrs.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d secure.wlxrs.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d rsi.hotmail.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d rsi.hotmail.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d ows.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d ows.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.0.130 -d config.messenger.msn.com -p tcp --dport 443 -j DROP
iptables -A INPUT -s 192.168.0.130 -d config.messenger.msn.com -p tcp --dport 443 -j DROP
........
Engraçado que as mesmas regras para orkut, twitter, facebook em HTTPS funcionam perfeitamente......ou seja, a pagina de login da live esta usando algum outro site...
se alguem puder me ajudar
Valeu!