Re: Allow Skype

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"Newbie" <Newbie@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BF7D3147-3F52-47B4-A4CA-A8777F277D89@xxxxxxxxxxxxxxxx
Hello,

If I allow http and https to external, then I can use Skype no porblem at
all.
If I limited http and htpps to some sites(including skype.com), then I can
not login Skype.

Can I fix this problem?

The short answer is:
No. Because Skype client program calls skype.com for its binary updates
only.
To make Skype communications work you should allow Skype client program to
contact a set of another external sites called "super nodes". You have to
allow them as long as skype.com

Some boring details:
Skype client builds a list of available super nodes dynamically, but there
is a list of 7 or 8 of them are hardcoded into the Skype client binary, so
[theoretically] you can monitor, which sites Skype client is trying to
contact and allow them accordingly.
Because Skype client is using proprietary protocols, it is very hard to
suggest anything more particular in this case. You could also want to read
reports regarding Skype protocol research made by some enthusiasts. Here is
an example:

An Analysis of the Skype Peer-to-Peer Internet Telephony Protocol by Salman
A. Baset and Henning Schulzrinne (Skype v1.4)
http://www1.cs.columbia.edu/~salman/publications/skype1_4.pdf

Regards,
Andrew


.



Relevant Pages

  • Re: [Full-disclosure] [inbox] Re: [ Capture Skype trafic ]
    ... but that document outlines HOW Bluecoat can and does block Skype. ... A packet or protocol anaylizer Proxy will block anything that is NOT ... Skype does not conform to HTTP ...
    (Full-Disclosure)
  • Re: In the news: Soon to be published, Skype back-door trojan code?
    ... Is there any initiative or attempts to reverse engineer its protocol? ... The person who completely reverse engineers skype probably destroys it. ... If you can write a skype client than the spammers can write skype spam ... Skype appears to contain various law enforcement intercept facilities ...
    (Fedora)
  • New "Skype for 3" client with text chat.
    ... After over 18 months of being told that text chat is "coming soon", 3 have finally released a version of their Skype client which supports chat on x-series phones: ... If I go to the Skype page linked from the services section of my3 it still only offers me the old version ... A notification of an incoming chat message is displayed on screen (even if the Skype app is minimised) but there is no corresponding beep. ...
    (uk.telecom.mobile)
  • Re: New "Skype for 3" client with text chat.
    ... have finally released a version of their Skype client which supports chat ... You can test chat by ...
    (uk.telecom.mobile)
  • Re: [opensuse] something like skype, but secure?
    ... Bypassing the firewall is the beauty of skype, ... methods in skype will connect to any skype client that is NOT behind ... So the un-firewalled machine routes traffic for the two firewalled ...
    (SuSE)