<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Instant Messaging detection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364965#M97169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;some signatures should already be there. see details here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/front.x/csec/idsAllList.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/front.x/csec/idsAllList.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yahoo Messenger Activity  &lt;/P&gt;&lt;P&gt;Siganture Id/Sub Id  11200/0  &lt;/P&gt;&lt;P&gt;Signature Description  This signature fires when a Yahoo Messenger client login attempt to the default TCP port 5050 is detected.  &lt;/P&gt;&lt;P&gt;IDS Version  S46  &lt;/P&gt;&lt;P&gt;Alarm Level  0  &lt;/P&gt;&lt;P&gt;Benign Triggers  Normal Yahoo Messenger activity will cause this signature to fire.  &lt;/P&gt;&lt;P&gt;Signature Type  NETWORK  &lt;/P&gt;&lt;P&gt;Signature Structure  ATOMIC  &lt;/P&gt;&lt;P&gt;Implementation  CONTENT  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Related Vulnerabilities  &lt;/P&gt;&lt;P&gt;3843  Instant Messaging  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Siganture Id/Sub Id  11201/0  &lt;/P&gt;&lt;P&gt;Signature Description  This signature fires when an MSN new connection attempt to the default TCP port 1863 is detected.  &lt;/P&gt;&lt;P&gt;IDS Version  S46  &lt;/P&gt;&lt;P&gt;Alarm Level  0  &lt;/P&gt;&lt;P&gt;Benign Triggers  Normal use of MSN instant messaging clients will cause this signature to fire.  &lt;/P&gt;&lt;P&gt;Signature Type  NETWORK  &lt;/P&gt;&lt;P&gt;Signature Structure  ATOMIC  &lt;/P&gt;&lt;P&gt;Implementation  CONTENT  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Related Vulnerabilities  &lt;/P&gt;&lt;P&gt;3843  Instant Messaging  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Feb 2005 20:39:37 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2005-02-02T20:39:37Z</dc:date>
    <item>
      <title>Instant Messaging detection</title>
      <link>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364964#M97165</link>
      <description>&lt;P&gt;I am using a 4235 and need to be able to detect when a user is using any type of IM or P2P application.  I know others are able to do this but they are using a different brand IDS.  Any help or ideas whould be very helpful.  My infrastructure is all Extreme so NBAR is not an option.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364964#M97165</guid>
      <dc:creator>napoleoncrowe</dc:creator>
      <dc:date>2019-03-10T09:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Instant Messaging detection</title>
      <link>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364965#M97169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;some signatures should already be there. see details here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/front.x/csec/idsAllList.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/front.x/csec/idsAllList.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yahoo Messenger Activity  &lt;/P&gt;&lt;P&gt;Siganture Id/Sub Id  11200/0  &lt;/P&gt;&lt;P&gt;Signature Description  This signature fires when a Yahoo Messenger client login attempt to the default TCP port 5050 is detected.  &lt;/P&gt;&lt;P&gt;IDS Version  S46  &lt;/P&gt;&lt;P&gt;Alarm Level  0  &lt;/P&gt;&lt;P&gt;Benign Triggers  Normal Yahoo Messenger activity will cause this signature to fire.  &lt;/P&gt;&lt;P&gt;Signature Type  NETWORK  &lt;/P&gt;&lt;P&gt;Signature Structure  ATOMIC  &lt;/P&gt;&lt;P&gt;Implementation  CONTENT  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Related Vulnerabilities  &lt;/P&gt;&lt;P&gt;3843  Instant Messaging  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Siganture Id/Sub Id  11201/0  &lt;/P&gt;&lt;P&gt;Signature Description  This signature fires when an MSN new connection attempt to the default TCP port 1863 is detected.  &lt;/P&gt;&lt;P&gt;IDS Version  S46  &lt;/P&gt;&lt;P&gt;Alarm Level  0  &lt;/P&gt;&lt;P&gt;Benign Triggers  Normal use of MSN instant messaging clients will cause this signature to fire.  &lt;/P&gt;&lt;P&gt;Signature Type  NETWORK  &lt;/P&gt;&lt;P&gt;Signature Structure  ATOMIC  &lt;/P&gt;&lt;P&gt;Implementation  CONTENT  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Related Vulnerabilities  &lt;/P&gt;&lt;P&gt;3843  Instant Messaging  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 20:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364965#M97169</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-02-02T20:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Instant Messaging detection</title>
      <link>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364966#M97175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have added a considerable number of signatures in the last few releases. For example, signatures 11019-11020, 11028-11031, 11200-11232 have been added in release S140. These signatures add greatly to our current coverage of IM and P2p products as well as providing more granular activity monitoring. However, They have been disabled by default. To use them, you have to enable them. We are in the process of releasing a few more soon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 21:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364966#M97175</guid>
      <dc:creator>rupadras</dc:creator>
      <dc:date>2005-02-02T21:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Instant Messaging detection</title>
      <link>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364967#M97176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just updated the box to 140 so I'll go ahead and enable those.  Thanks a ton! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 14:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/instant-messaging-detection/m-p/364967#M97176</guid>
      <dc:creator>napoleoncrowe</dc:creator>
      <dc:date>2005-02-03T14:48:54Z</dc:date>
    </item>
  </channel>
</rss>

