Old 11-17-2007, 04:26 PM   #1 (permalink)
CYa
Newbie
 
Join Date: Nov 2007
Posts: 4
CYa is on a distinguished road
Smile How to block emule? (solved)

Hi there!

I work as a network administrator in a academic enviroment and I am giving a try to an untangled box.

I need to block emule . Already did with messenger by "Protocol Control" without problems but emule keeps on working.

Thanks for your software.

_________________
using untangle 5.0.3

Last edited by CYa; 11-18-2007 at 04:04 PM.. Reason: being more specific
CYa is offline  
Old 11-17-2007, 07:36 PM   #2 (permalink)
Untangle Ninja
 
juank's Avatar
 
Join Date: Aug 2007
Location: Athens
URLs submitted: 46
Posts: 1,474
juank is on a distinguished road
Default

Cya,

It will keep working (emule) IF you set the block rule AFTER the emule connection was open.

I think that if you re-start Untangle, that will force your EMULE clients to open a new connection, but this time your Protocol Control rule WILL block it.
__________________
--------------------------------
Juan Machado
--------------------------------
juank is offline  
Old 11-18-2007, 12:49 PM   #3 (permalink)
CYa
Newbie
 
Join Date: Nov 2007
Posts: 4
CYa is on a distinguished road
Default

I tested setting the rule before and after to check it. Behaves as you said, thanks for the inpunt Juan. Still have some troubles.

As I did not see any specific pattern for edonkey/emule I added the following pattern from l7 website:

^[\xc5\xd4\xe3-\xe5].?.?.?.?([\x01\x02\x05\x14\x15\x16\x18\x19\x1a\x1b\x1c\x20\x 21\x32\x33\x34\x35\x36\x38\x40\x41\x42\x43\x46\x47 \x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x 54\x55\x56\x57\x58[\x60\x81\x82\x90\x91\x93\x96\x97\x98\x99\x9a\x9b\x 9c\x9e\xa0\xa1\xa2\xa3\xa4]|\x59................?[ -~]|\x96....$)

The previous pattern works "very well". In fact, blocks emule protocol and http traffic too.

Any suggestions?
CYa is offline  
Old 11-18-2007, 02:01 PM   #4 (permalink)
CYa
Newbie
 
Join Date: Nov 2007
Posts: 4
CYa is on a distinguished road
Default

Some information from l7 sourceforge forum:

"> since protocol obfuscation in v0.47c was introduced, my router with
> l7-filter (which up to then worked like clockwork) does not recognize
> emule traffic. Is there anything I can do, before our dear
> pattern-makers develop a better pattern?

No, there's nothing you can do without a better pattern. You should also
know that there is a possibility that there is no better pattern. If
emule protocol obfustication means that all traffic is encrypted, then
l7-filter will not be able to match it. However, I have not gotten a
chance to research this. (I encourage others to work on it, since it may
be a while if it's just me.)

-Matthew"
CYa is offline  
Old 11-18-2007, 04:02 PM   #5 (permalink)
CYa
Newbie
 
Join Date: Nov 2007
Posts: 4
CYa is on a distinguished road
Default

By trying again and again I have found a way to block the last emule version (0.48a without obfuscation):

^[\xc5\xd4\xe3-\xe5]

Hope this helps.

Last edited by CYa; 11-19-2007 at 02:44 AM..
CYa is offline  
Old 02-15-2009, 06:09 PM   #6 (permalink)
Newbie
 
Join Date: Feb 2009
Posts: 1
brownstone is on a distinguished road
Default

using the signature it is now detecting the emule but it still make a connection :-(
brownstone is offline  
Old 02-15-2009, 06:40 PM   #7 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

You'll need to do a Google search to see how emule operates. You might be able to catch it with:

1. Protocol Control - if you can get correct signatures for EACH version of emule in use on your network.
2. Firewall - Blocking access to IPs that make the connection between your user and their emule peers

The people that create these things always try to stay one step ahead, and are often able to do so. Network people spend an infinite number of hours trying to stay even with the people that are trying to stay one step ahead. It has often been pointed out on these forums that the best prevention is to ID your user and tell him that you will have his nads hanging from the doorjam if he doesn't stop using torrents at work/school (where ever you are). In an economy like this, people would not want to lose their job because they just gotta steal one more album.
__________________
This space reserved for profound thought.....which does happen on occasion."
mdh is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:48 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2