i try update this threads....

in my network using squid proxy for all internet access
after capture the access.log
teamviewer have several server

main server teamviewer
1. http://ping3.dyngate.com
2. masterxx.teamviewer.com
 where xxx = 1 until 17
 so become master1.teamviewer.com until master17.teamviewer.com

so i made block dst domain in squid.conf .
and teamviewer client can't working.
i try scan port was using for teamviewer server
# nmap ping3.dyngate.com

Starting Nmap 4.76 ( http://nmap.org ) at 2010-03-26 23:06 WIT
Warning: Hostname ping3.dyngate.com resolves to 4 IPs. Using
Interesting ports on server340.teamviewer.com (
Not shown: 997 filtered ports
80/tcp   open  http
843/tcp  open  unknown
3389/tcp open  ms-term-serv

Nmap done: 1 IP address (1 host up) scanned in 17.25 seconds

# nmap master1.teamviewer.com

Starting Nmap 4.76 ( http://nmap.org ) at 2010-03-26 23:06 WIT
Interesting ports on master.dyngate.com (
Not shown: 998 filtered ports
80/tcp  open  http
843/tcp open  unknown

ini hasil scan client teamviewer
# nmap

Starting Nmap 4.76 ( http://nmap.org ) at 2010-03-26 23:12 WIT
Interesting ports on server404.teamviewer.com (
Not shown: 997 filtered ports
80/tcp   open  http
843/tcp  open  unknown
3389/tcp open  ms-term-serv

Nmap done: 1 IP address (1 host up) scanned in 24.82 seconds

so add in pf for blockerd port 843 & 3389

just that and teamviewer client can't working....
i hope this will be blocked teamviewer.

On Sat, Mar 20, 2010 at 1:22 AM, Siju George <sgeorge...@gmail.com> wrote:
> On Fri, Mar 19, 2010 at 10:14 PM, Steve Shockley <steve.shock...@shockley.net>
>> Presumably you're trying to block it with an OpenBSD firewall.
> Yes :-)
>>Analyze the
>> protocol, you can probably stop it with a transparent proxy that disallows
>> CONNECT requests.
> Could you please explain?
>> Or, http://lmgtfy.com/?q=teamviewer+block&l=1
> The first thing I did :-)
> thanks
> --Siju


