How to block Remote Desktop software?

Dec 02, 2008 3 Replies
How to block Remote Desktop software? open original image

Does anyone know of an effective way to block remote desktop applications like GoToMyPC.com, PCanywhere, Fog Creek Copilot etc. at the network level, that doesn't require me to manually find the relevant IP addresses, etc.?



For example does someone host updated IPS signatures, or updated IP lists that could be used in an IPS?



Has anyone else on this list had this challenge, and how did you solve it?



Kind regards, Daniel Tams


Why do you allow unrestricted outbound?

Why does your company not just allow outbound to specific sites that are approved?

I work with Proventia stuff frequently and I know IBM ISS Proventia IPS has signatures for these:

formatting link
formatting link
formatting link
formatting link
The protocol detection signatures are generally low or medium, but you could configure them in a profile to drop such traffic if you use the IPS inline in blocking mode.

Being more draconian in egress and inbound filtering can also deal with this, but sensing it on a network level often has uses in environments that aren't as militaristically locked down as other posters suggest. Also, generally those intent on using such technologies will use ports that are allowed to subvert whatever rote policies are in place.

I think Untangle

formatting link
does at least some of these in its various applications (webfilter, protocol filter, etc). gr

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required