Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Port Explorer
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 19th, 2002, 11:46 AM
Disciple's Avatar
Disciple Disciple is offline
Frequent Poster
 
Join Date: Nov 2002
Location: Ellijay, Georgia - USA
Posts: 292
Default Socket Spy Behavior Question

In making the switch from Atelier's AWPTA to Port Explorer, and in-order to get a better feel for PE, I have a question about how Socket Spy functions. If the answer is in the help file please forgive me, for it did not catch my attention.

Is it possible to spy on 2 or more processes/sockets at the same time? i.e. have say an IE process/socket and a process/socket for say svchost.exe in the list at the same time, and be able to switch between the 2. My reasoning is, to verify that a suspicious item is not using an established/allowed process/socket for communication.

TIA for all answers.
__________________
Disciple - Team Z
And now abide faith, hope, love, these three; but the greatest of these is love. 1 Cor. 13:13
  #2  
Old November 19th, 2002, 12:01 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:Socket Spy Behavior Question

Hi Disciple,
It is described very fine in the Helpfile under "Advanced > Packet sniffing witj socket spy" with screen shots and lot of fine information i'm sure you'll enjoy reading and trying!
__________________
Jooske
"o_o"
  #3  
Old November 19th, 2002, 12:06 PM
Wayne - DiamondCS's Avatar
Wayne - DiamondCS Wayne - DiamondCS is offline
Security Expert
 
Join Date: Jul 2002
Location: Perth, Oz
Posts: 1,533
Default Re:Socket Spy Behavior Question

This page (out of the helpfile in the Advanced section) should be of some interest - http://www.diamondcs.com.au/portexplorer/index.php?page=packetsniffer

... but to answer your question, yes - you can spy on individual sockets and processes, as many as you like, and yes even at the same time. For example, you might want to spy on port 21 of your FTP client, but not any other ports - PE lets you easily do this. However if you DO want to spy on the whole process and all of its sockets (including ones that are created later), then PE also lets you easily do this. I haven't got any hard numbers on hand at the moment but you can basically add as many sockets and processes to the spy list as you like, and easily remove them later whenever you want with just a couple of mouseclicks.

Best regards,
Wayne
__________________
DiamondCS (Est. 1986) - Celebrating 20 Years ...
Home of Port Explorer, ProcessGuard, and check out all our other freeware security tools!
  #4  
Old November 19th, 2002, 12:51 PM
Disciple's Avatar
Disciple Disciple is offline
Frequent Poster
 
Join Date: Nov 2002
Location: Ellijay, Georgia - USA
Posts: 292
Default Re:Socket Spy Behavior Question

Thanks Jooksie and Wayne for your replies, and patience. I now know it's time for my eye exam, as I totally missed socket(s)/process(es) in the manual.
__________________
Disciple - Team Z
And now abide faith, hope, love, these three; but the greatest of these is love. 1 Cor. 13:13
  #5  
Old November 19th, 2002, 02:39 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:Socket Spy Behavior Question

No, your mouse needs to learn the double click to open the book icon at the right page.
In the Helpfile > Utilities > Socket Spy is a small introduction with links to that part.
Glad you found it!
__________________
Jooske
"o_o"
  #6  
Old November 20th, 2002, 12:38 AM
Jason_DiamondCS's Avatar
Jason_DiamondCS Jason_DiamondCS is offline
Former DCS Moderator
 
Join Date: Nov 2002
Location: Perth, Western Australia
Posts: 1,046
Default Re:Socket Spy Behavior Question

The Hard Numbers :-

You can spy on up to 128 different process ID's at a time combined with as many individual sockets as you want.

So there is no limit on individual sockets, you can spy on each and every socket if you had 10000 of them.

But only a maximum of 128 "whole" processes can be monitored at a time, if you understand what I mean? I could easily extend that to more though but I think 128 is enough
-Jason-
__________________
Jason - DiamondCS Programmer
DiamondCS (Est. 1986) - The System Security Specialists
CryptoSuite - Protect your information today!
TDS - Powerful anti trojan software
  #7  
Old November 20th, 2002, 01:20 PM
Disciple's Avatar
Disciple Disciple is offline
Frequent Poster
 
Join Date: Nov 2002
Location: Ellijay, Georgia - USA
Posts: 292
Default Re:Socket Spy Behavior Question

Quote:
quoting: Jason / DiamondCS link=board=7;threadid=5006;start=0#32808 date=1037770705]
The Hard Numbers :-

You can spy on up to 128 different process ID's at a time combined with as many individual sockets as you want.

So there is no limit on individual sockets, you can spy on each and every socket if you had 10000 of them.

But only a maximum of 128 "whole" processes can be monitored at a time, if you understand what I mean? I could easily extend that to more though but I think 128 is enough
-Jason-


That ought to keep me and any other most curious person busy for a loooooong time. Maybe we have too much time on our hands?
__________________
Disciple - Team Z
And now abide faith, hope, love, these three; but the greatest of these is love. 1 Cor. 13:13
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Port Explorer « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:06 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums