sz.tencent.com 6 1. 144 . 238 . 145
sz2.tencent.com 6 1. 144 . 238 . 146
sz3.tencent.com 202. 104. 129.25 1
sz4.tencent.com 202. 104. 129.254
sz5.tencent.com 6 1. 14 1. 194.203
sz6.tencent.com 202. 104. 129.252
sz7.tencent.com 202. 104. 129.253
After blocking the connection of port 8000, QQ will also connect with ports 800 1 of udp and 80001of tcp. Therefore, blocking rules can be formulated based on ports.
After blocking the data packets of the above ports with a firewall, it is found that QQ will also be connected through tcp ports 80 and 443. If these two ports are blocked, it will affect users' normal internet access, so the ip address of the server can only be used as a rule. Through experiments, we found that the following QQ servers can establish connections through ports 80 and 443:
2 18. 17.2 17. 106
2 19. 133.40.95
2 19. 133.40.97,
2 19. 133.40. 157,
2 19. 133.40. 177,
2 19. 133.40.73,
2 19. 133.40. 189
2 18. 18.95. 153
2 18. 17.209.23
202. 104. 129.253
2 18. 17.209.42
After shielding these IPS, QQ has basically been unable to log in.
In the experiment, we also found that the Config.db file under the QQ installation directory records the address of the QQ server, which is completely consistent with what we found above.
Therefore, when using firewall to prevent users from surfing the Internet using QQ, in addition to blocking ports 8000 and 800 1 of tcp and udp, it is also necessary to block the connection with QQ server. The following lists the QQ server IP found in the experiment and on the Internet:
6 1. 14 1. 194.203
6 1. 144.238. 145/ 146/ 149/ 155
6 1. 172.249. 135
65.54.229.253
202.96. 170. 164
202. 104. 129. 15 1/25 1/252/253/254
2 1 1. 157.38.38
2 18. 17.209.23/42
2 18. 17.2 17. 106
2 18. 18.95. 153/ 165
219.133.40.21/73/89/90/92/95/97/157/177/189.
Although the above methods can block QQ connection, if Tencent adds a new QQ server, QQ can still log in.
In addition, third-party proxy software such as NEC E-BORDER is used to support Socks5 of Anonymous? It is still possible for agents to bypass and log in to use QQ.