|
![]() |
|
| Author |
|
|||||||
|
Viper119
Posts: 1016
Location: UK
|
Hey, I'm looking to monitor the usage of MSN on the company network, i've checked out a bunch of the freerange crappy programs out there, like MSN Sniffer 2, MSN Monitoring etc. They are fine for intercepting and monitoring individual conversations, but they don't offer any real reporting ability. My main goal is to be able to generate a report that details how much MSN traffic each workstation (IP/MAC address) on the network is transmitting in a given time period. I've looked at Ethereal, Ultrasniff, and Microsoft's Network Monitoring 3, but i've never used these before and it's looking a bit tricky to get it to only pick up MSN traffic. I know alot of people on this forum work in IT and Network Admin roles, was wondering if anyone else has had to do, or knows how to do this? Many thanks |
|||||||
| #0 12:04am 17/04/07 |
|
|||||||
|
system
|
--
|
|||||||
| #0 |
|
|||||||
|
TicMan
Posts: 1901
Location: Brisbane, Queensland
|
Snort could possibly help out in this situation. I've only ever seen it running after it was setup by some very skilled people and it was able to generate reports on traffic across the network by protocol.
|
|||||||
| #1 08:59am 17/04/07 |
|
|||||||
|
CaPt0
Posts: 5853
Location: Brisbane, Queensland
|
Use a transparent proxy or similar to generate reports?
If you don't filter the traffic then you won't have a chance to get any info. |
|||||||
| #2 09:59am 17/04/07 |
|
|||||||
|
trog
AGN Admin
Posts: 20366
Location: Brisbane, Queensland
|
MSN is really tricky from what I've looked at, using a heap of ports and protocols to try to work (ie, if you block one it just tries using another one). I can see why MS did it like that (to stop idiot newbs having problems) but at the same time, it'd be nice if they provided sysadmins with some comprehensive info about how to block it.
|
|||||||
| #3 06:44pm 17/04/07 |
|
|||||||
|
Spook
Posts: 18326
Location: Brisbane, Queensland
|
im glad you dont work at my work viper
|
|||||||
| #4 06:55pm 17/04/07 |
|
|||||||
|
Opec
Posts: 4521
Location: Brisbane, Queensland
|
Here's an alternative idea:
- Block all MSN ports; - Install SOCKS server and config MSN to use that; - Generate usage report on SOCKS server. So you can isolate the MSN traffic to other types of traffic on your network. I know this won't stop them from using web MSN but you couldn't really do that easily anyway. Just my $0.02. Edit: This product might do what you want (emphasis' mine): http://www.eeye.com/html/products/Iris/features.html
last edited by Opec at 20:14:53 17/Apr/07 |
|||||||
| #5 08:14pm 17/04/07 |
|
|||||||
|
gimpy
Posts: 1441
Location: Brisbane, Queensland
|
I installed one of these at a place I worked at: http://www.contentkeeper.com.au/
Basically you sit it between your office network and the gateway and you can see everything that goes on. You'd be surprised how many people visit www.rsvp.com.au in work time. (It was in the top 10, along with seek.com.au, lol) You want to disable MSN/or any IM? No problem, just tick a box. Yes, it will kill any "work arounds". Hooks into AD using LDAP. So any user/group specific policies are easily configurable. Might be worth sending an email to info@contentkeeper.com telling them exactly what you want to see if the advanced reporting module does it. You can also run it in "quiet mode", so it doesn't block a thing and it is impossible for users to know it is running.. But at the same time, it generates VERY detailed reports with the users login ID attached, and how much company time they wasted surfing the net.. :) (OUCH?) |
|||||||
| #6 01:56am 18/04/07 |
|
|||||||
|
Viper119
Posts: 1017
Location: UK
|
Excellwnt responses, thanks guys! I'm checking it all out Yeah you are right, it is very tricky... and Spook, my work gives alot of freedom, we don't block anything, but we expect people not to abuse that trust, and right now a few key people are just taking the piss. All i really want is like a top 10 users list so we can publish it and action accordingly. In a related story I was checking out MSN Sniffer 2, it intercepts the actual conversations, and the HR chick was actually having cyber sex with her boyfriend on msn.... it was like f***ing 11AM on a Tuesday. |
|||||||
| #7 08:07am 18/04/07 |
|
|||||||
|
SCOGGEX
Posts: 712
Location: Brisbane, Queensland
|
noone likes an MSN nazi mate.
|
|||||||
| #8 08:09am 18/04/07 |
|
|||||||
|
Eds
Posts: 8255
Location: Brisbane, Queensland
|
You may want to also make sure your IT policy and employee contracts state that they are subject to "big brother" type stuff to cover your ass.
|
|||||||
| #9 08:22am 18/04/07 |
|
|||||||
|
TicMan
Posts: 1918
Location: Brisbane, Queensland
|
In a related story I was checking out MSN Sniffer 2, it intercepts the actual conversations, and the HR chick was actually having cyber sex with her boyfriend on msn.... it was like f***ing 11AM on a Tuesday. Logs or lying! |
|||||||
| #10 09:29am 18/04/07 |
|
|||||||
|
trog
AGN Admin
Posts: 20371
Location: Brisbane, Queensland
|
Basically you sit it between your office network and the gateway and you can see everything that goes on. You'd be surprised how many people visit www.rsvp.com.au in work time. (It was in the top 10, along with seek.com.au, lol)ahaha really |
|||||||
| #11 10:21am 18/04/07 |
|
|||||||
|
parabol
Posts: 3179
Location: Brisbane, Queensland
|
A work-mate of mine had a nice setup a while back.
Dual-monitor environment, with Seek.com.au on one monitor facing away from the boss's office, with the second monitor (boss-visible) set up with a bash script that scrolled useless technical jargon on the screen to make him look busy while he was finding a better-paying job. |
|||||||
| #12 10:31am 18/04/07 |
|
|||||||
|
gimpy
Posts: 1443
Location: Brisbane, Queensland
|
HR chick was actually having cyber sex with her boyfriend on msn If you think chicks in HR actually do any work you're sadly mistaken. ahaha really Yups, company was in a bad state at the time. Had just been taken over and morale was under the floor boards. It was top 10 websites sorted by usage.. So like, all the pictures and stuff would account for a lot of it. The amount of individual users using the site wasn't that high. But those who were got it into the top 10. I guess in a way, it showed that most people were doing the right thing, if rsvp.com.au traffic was in the top 10. I felt bad about the whole thing cause I didn't agree with it, and told all my friends not to look at dodgey websites at work anymore.. |
|||||||
| #13 02:04pm 18/04/07 |
|
|||||||
|
gimpy
Posts: 1444
Location: Brisbane, Queensland
|
||||||||
| #14 02:10pm 18/04/07 |
|
|||||||
|
Spook
Posts: 18334
Location: Brisbane, Queensland
|
im totally astounded by how popular rsvp is
i know heaps of peeps that use it regularly and they are all getting plenty |
|||||||
| #15 02:38pm 18/04/07 |
|
|||||||
|
infi
Posts: 5625
Location: Brisbane, Queensland
|
0_o net monitors scare me... i could never introduce that stuff at work cause I am the worst offender.
last edited by infi at 14:49:24 18/Apr/07 |
|||||||
| #16 02:49pm 18/04/07 |
|
|||||||
|
Captain America
Posts: 1337
Location: Gold Coast, Queensland
|
websense lol
|
|||||||
| #17 03:25pm 18/04/07 |
|
|||||||
|
Astroboy
Posts: 4089
Location: Germany
|
... and went and made a profile on rsvp.com.au AMIRITES?! LOL Dentist thing didnt go too well, huh? |
|||||||
| #18 03:31pm 18/04/07 |
|
|||||||
|
demon
Posts: 2758
Location: Brisbane, Queensland
|
the company i work for use msn as a comms tool for international communications... i suggested irc but was over-ruled by stupid noobheds :P since then a couple of i.t. blokes have tried to shutdown my irc'ing.. & failed. :D viva teh eye are see yoh.
|
|||||||
| #19 03:33pm 18/04/07 |
|
|||||||
|
system
|
--
|
|||||||
| #19 |
|
|||||||
|
| ||||||||