<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Blink Beta 3.1 Feedback</title><link>http://forums.eeye.com/forums/9.aspx</link><description>This forum is used for beta users of Blink 3.1. Interested in the Beta, look here for the download location.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>Re: HTTP : Suspicious HTTP method from Skype</title><link>http://forums.eeye.com/forums/thread/1104.aspx</link><pubDate>Tue, 04 Sep 2007 14:54:01 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:1104</guid><dc:creator>fairfax</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/1104.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=9&amp;PostID=1104</wfw:commentRss><description>&lt;p&gt;Yeah, that started to happen to me as well as soon as I downloaded the newest version of Skype. It never happened before.&lt;/p&gt;&lt;p&gt;Best,&lt;/p&gt;&lt;p&gt;Art&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: HTTP : Suspicious HTTP method from Skype</title><link>http://forums.eeye.com/forums/thread/985.aspx</link><pubDate>Mon, 13 Aug 2007 02:13:15 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:985</guid><dc:creator>lnicula</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/985.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=9&amp;PostID=985</wfw:commentRss><description>&lt;p&gt;This is caused by Skype using a proprietary protocol on a well known port such as 80 (HTTP). Blink tries to interpret it as HTTP and guess what, it will find many things that don&amp;#39;t seem right.&lt;/p&gt;
&lt;p&gt;It is possible to whitelist applications altogether for the IPS engine (they are still protected by other layers) so if you still have this problem, let me know and I will send you instructions on how to do it.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: HTTP : Suspicious HTTP method from Skype</title><link>http://forums.eeye.com/forums/thread/967.aspx</link><pubDate>Sun, 12 Aug 2007 15:59:54 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:967</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/967.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=9&amp;PostID=967</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;GameFanatic:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;I have already Kevlar&amp;#39;ed Skype.exe but still get these in the log.&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Have you tried excluding the entire Program Files group for Skype, not just the .exe?&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It almost looks as though Blink thinks that there is an Buffer Overflow trying to take place, or &amp;quot;invalid&amp;quot; data input in Skype.&amp;nbsp; I think this when I see the phrase &amp;quot;A client tried to send a request with a method that has a &lt;b&gt;suspicious size&lt;/b&gt;&amp;quot;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;br /&gt;&lt;font face="courier new,courier" size="2"&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;GameFanatic:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;Method Size : 42-143&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;font face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have never used Skype before, but are there any settings in it that control how large voice data packets are allowed to be in it?&amp;nbsp; Maybe compare the defaults with the # above and then that would tell you if the allotted amount was exceeded etc.&amp;nbsp; Just an idea that came to mind.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="courier new,courier" size="2"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>HTTP : Suspicious HTTP method from Skype</title><link>http://forums.eeye.com/forums/thread/446.aspx</link><pubDate>Wed, 20 Jun 2007 10:30:44 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:446</guid><dc:creator>GameFanatic</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/446.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=9&amp;PostID=446</wfw:commentRss><description>&lt;p&gt;Getting lots of these in the logs.&amp;nbsp; Are they bad?&amp;nbsp; What can I do to stop these if not?&lt;/p&gt;
&lt;p&gt;Event ID: BLINK-BAM-5002&lt;/p&gt;
&lt;p&gt;Severity: High&lt;/p&gt;
&lt;p&gt;Description: A client tried to send a request with a method that has a suspicious size&lt;/p&gt;
&lt;p&gt;Method: &lt;font face="Courier New"&gt;êÅØ`û¯Ù&#x1D;¤à&#x16;v\¢÷0&#x1B;š&#x4;&#x13;&#x4;äøëÜûd™&amp;amp;&#x11;TÚ8Y&#x19;VÚ˜2`Øû&#x5;à&#x13;_,”ÿ&#x18;ká.&#x1B;&#xF;l/&#x16;1Jnx¼&#x1D;óìë°ì&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2: &lt;font face="Courier New"&gt;Ò xm÷rÎ›{áÐhÎ²°ËvR&#x1D;ÿ”&#x1C;*®|Nf°–ø÷«óïvu,XÔcPß6ªÉ&#x2;l´ÞËvp´v„eºR~A{&#x1E;›ÑìœäŸ&amp;amp;…–¸€Í7T¢8~.š3’ë[®)»&#x18;¶gcù&#x1B;&#x1;ÉD/4Ó(yÖàœ8k‹7i×û&#x4;G±øñÌ Hf1;¯&#x11;š«O&amp;gt;^ý‡µmÖ|bRJ·&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Courier New"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3: ËXÀ|a+°®¿ÜÓÝ¡•ƒÉ·Èr&#x8;æ&amp;lt;&#x13;M&#x3;ÖU&#x3;˜±˜‡yÉã&#x6;Á®ß³&#x3;ó¼O&#x1B;V±¬‚šÎHƒÃÝ“ê¤%d“®ç®gðSmC{Ô#YÚòRë.ãëôdi&amp;nbsp;g!i¸.&#x18;\&#x12;æ°r»uµ&#x1E;žÊ)Ðá–E«j±ÓRÞù´+\:§åœ&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Courier New"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4: 8ŸÆÉBj”¢Ëv€v®Ðó&#xF;ÐG&#x19;ì&#x10;·P&#x4; l…c6&#x1;B…‘Uß&amp;quot;wœ«8p´&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Courier New"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5: u+&#x1D;‹à¦% &#x1E;®ô&#x16;X?Ne‹ÌÒbnÕÀ&#x15;0Ì&#x6;èn}xov2&#x12;ã³xmš &#x1F;AŠ•üwuøÁyÛ8·J©ž:1o°J&#x14;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;Process Path: C:\Program Files\Skype\Phone\Skype.exe&lt;/p&gt;
&lt;p&gt;Attacker IP: 124.254.82.116, 89.149.56.37, 203.84.186.45, 202.84.110.172&lt;/p&gt;
&lt;p&gt;Action: Logged event&lt;/p&gt;
&lt;p&gt;Victim IP: 192.168.xxx.xxx&lt;/p&gt;
&lt;p&gt;Alert: No&lt;/p&gt;
&lt;p&gt;Protocol: TCP&lt;/p&gt;
&lt;p&gt;Attacker Port 22925, 16097, 1808, 1289, 1521, 22925&lt;/p&gt;
&lt;p&gt;Method Size : 42-143&lt;/p&gt;
&lt;p&gt;Victim Port 58223&lt;/p&gt;
&lt;p&gt;I have already Kevlar&amp;#39;ed Skype.exe but still get these in the log.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>