<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Signature for GoogleTalk (Google Talk) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855933#M85383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've never tested, but perhaps you can pilfer from these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stolen from Bleeding edge Snort rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#by Mark Tombaugh&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 5222 (msg:"BLEEDING-EDGE POLICY Google Talk (Jabber) Client Login"; flow:established,to_server; content:"gmail.com"; nocase; content:"jabber"; nocase; distance:9; within:6; classtype:policy-violation; reference:url,talk.google.com; reference:url,www.xmpp.org; sid:2002327; rev:2;)&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"BLEEDING-EDGE POLICY Google Talk TLS Client Traffic"; flow:established,to_server; content:"gmail.com"; nocase; content:"jabber"; nocase; distance:64; within:78; classtype:policy-violation; reference:url,talk.google.com; reference:url,www.xmpp.org; sid:2002330; rev:2;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Nov 2007 15:59:27 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2007-11-05T15:59:27Z</dc:date>
    <item>
      <title>Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855930#M85380</link>
      <description>&lt;P&gt;I was wondering if anyone has sucessfully created a custom signature to block GoogleTalk traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855930#M85380</guid>
      <dc:creator>jeremyarcher</dc:creator>
      <dc:date>2019-03-10T10:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855931#M85381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try blocking talk.google.com?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 02:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855931#M85381</guid>
      <dc:creator>mzeiser</dc:creator>
      <dc:date>2007-11-05T02:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855932#M85382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but the address range used for talk.google.com is also used for blogger.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead, I created a custom signature and blocked Regex URI talkgadget.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This does not block the GoogleTalk client though, only the web client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 15:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855932#M85382</guid>
      <dc:creator>jeremyarcher</dc:creator>
      <dc:date>2007-11-05T15:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855933#M85383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've never tested, but perhaps you can pilfer from these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stolen from Bleeding edge Snort rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#by Mark Tombaugh&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 5222 (msg:"BLEEDING-EDGE POLICY Google Talk (Jabber) Client Login"; flow:established,to_server; content:"gmail.com"; nocase; content:"jabber"; nocase; distance:9; within:6; classtype:policy-violation; reference:url,talk.google.com; reference:url,www.xmpp.org; sid:2002327; rev:2;)&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"BLEEDING-EDGE POLICY Google Talk TLS Client Traffic"; flow:established,to_server; content:"gmail.com"; nocase; content:"jabber"; nocase; distance:64; within:78; classtype:policy-violation; reference:url,talk.google.com; reference:url,www.xmpp.org; sid:2002330; rev:2;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 15:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855933#M85383</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-11-05T15:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855934#M85384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you can always just make the following records on your DNS Server and have it point to the loop-back addy. That should put an end to the google chat client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;talk.google.com - 127.0.0.1&lt;/P&gt;&lt;P&gt;talkx.l.google.com - 127.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 19:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855934#M85384</guid>
      <dc:creator>info</dc:creator>
      <dc:date>2007-11-05T19:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855935#M85385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried enabling signature 11204 (Jabber Activity)?  I believe this is googletalk traffic below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1175405913811111111 severity=low vendor=Cisco&lt;/P&gt;&lt;P&gt;  originator:&lt;/P&gt;&lt;P&gt;    hostId: xxxxxx&lt;/P&gt;&lt;P&gt;    appName: sensorApp&lt;/P&gt;&lt;P&gt;    appInstanceId: 446&lt;/P&gt;&lt;P&gt;  time: 2007/11/05 20:28:19 2007/11/05 20:28:19 UTC&lt;/P&gt;&lt;P&gt;  signature: description=Jabber Activity id=11204 version=S47&lt;/P&gt;&lt;P&gt;    subsigId: 0&lt;/P&gt;&lt;P&gt;    sigDetails: jabber:&lt;/P&gt;&lt;P&gt;  interfaceGroup:&lt;/P&gt;&lt;P&gt;  vlan: 0&lt;/P&gt;&lt;P&gt;  participants:&lt;/P&gt;&lt;P&gt;    attacker:&lt;/P&gt;&lt;P&gt;      addr: locality=IN x.x.x.x&lt;/P&gt;&lt;P&gt;      port: xxxxx&lt;/P&gt;&lt;P&gt;    target:&lt;/P&gt;&lt;P&gt;      addr: locality=OUT 209.85.163.125&lt;/P&gt;&lt;P&gt;      port: 5222&lt;/P&gt;&lt;P&gt;  context:&lt;/P&gt;&lt;P&gt;    fromAttacker:&lt;/P&gt;&lt;P&gt;000000  3C 73 74 72 65 61 6D 3A  73 74 72 65 61 6D 20 74  &lt;STREAM t=""&gt;&lt;/STREAM&gt;&lt;/P&gt;&lt;P&gt;000010  6F 3D 22 67 6D 61 69 6C  2E 63 6F 6D 22 20 78 6D  o="gmail.com" xm&lt;/P&gt;&lt;P&gt;000020  6C 3A 6C 61 6E 67 3D 22  65 6E 22 20 76 65 72 73  l:lang="en" vers&lt;/P&gt;&lt;P&gt;000030  69 6F 6E 3D 22 31 2E 30  22 20 78 6D 6C 6E 73 3A  ion="1.0" xmlns:&lt;/P&gt;&lt;P&gt;000040  73 74 72 65 61 6D 3D 22  68 74 74 70 3A 2F 2F 65  stream="&lt;A class="jive-link-custom" href="http://e" target="_blank"&gt;http://e&lt;/A&gt;&lt;/P&gt;&lt;P&gt;000050  74 68 65 72 78 2E 6A 61  62 62 65 72 2E 6F 72 67  therx.jabber.org&lt;/P&gt;&lt;P&gt;000060  2F 73 74 72 65 61 6D 73  22 20 78 6D 6C 6E 73 3D  /streams" xmlns=&lt;/P&gt;&lt;P&gt;000070  22 6A 61 62 62 65 72                              "jabber&lt;/P&gt;&lt;P&gt;  riskRatingValue: 45&lt;/P&gt;&lt;P&gt;  interface: ge2_1&lt;/P&gt;&lt;P&gt;  protocol: tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 21:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855935#M85385</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2007-11-05T21:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855936#M85386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this signature will fire but the GoogleTalk client continues to try and connect on different ports (443) until it reconnects.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 21:08:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855936#M85386</guid>
      <dc:creator>jeremyarcher</dc:creator>
      <dc:date>2007-11-05T21:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for GoogleTalk (Google Talk)</title>
      <link>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855937#M85387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think that this is the best option as well.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 21:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-signature-for-googletalk-google-talk/m-p/855937#M85387</guid>
      <dc:creator>jeremyarcher</dc:creator>
      <dc:date>2007-11-05T21:11:00Z</dc:date>
    </item>
  </channel>
</rss>

