Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 5th, 2007, 08:15 PM
yankinNcrankin's Avatar
yankinNcrankin yankinNcrankin is offline
Frequent Poster
 
Join Date: May 2006
Posts: 406
Lightbulb Here is some INFO on PowerShadows Outbound connecting

I ran several tests regarding the out bound and Inbound connections that PowerShadow makes when you start the program and here is the result which happens to be the same every time I launched the program. I even checked it with HEX and found nothing unusual if any one finds something weird about my attachment please reply, I may have missed something. I'll be more specific about this test: I have 2 computers. One with PowerShadow running and the other I used to packet sniff my network. The results I got after running PowerShadow for several sessions each lasting about 30 min, resulted in the same packets which you can view.
Attached Thumbnails
Click image for larger version

Name:	PowerShadow.png
Views:	18
Size:	41.5 KB
ID:	188189  


Last edited by yankinNcrankin : March 7th, 2007 at 03:45 AM.
  #2  
Old March 6th, 2007, 08:28 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Here is some INFO on PowerShadows Outbound connecting

Can't help with those outbounds but on my setup Powershadow's shadowtip.exe attempts a connection several minutes after executing the program and not at program startup.

Blocked with the new version of PCtools FW with no adverse effects.

Might add that sometimes ShadowSetting tries an outbound as well.
Name:  Shadow setting.jpg
Views: 295
Size:  17.2 KB

Last edited by Franklin : March 6th, 2007 at 08:35 PM.
  #3  
Old March 7th, 2007, 02:56 AM
yankinNcrankin's Avatar
yankinNcrankin yankinNcrankin is offline
Frequent Poster
 
Join Date: May 2006
Posts: 406
Default Re: Here is some INFO on PowerShadows Outbound connecting

The point of this was to show users of this program that I personally didn't find anything of concern about the outbound connecting of this program. Packets remained the same all the time and the information sent and recieved were the same. Very similar to when you use explorer to search drive(s) and are currently connected to the internet, it will also outbound connect for a split second sending similar information out to a specific address.

Last edited by yankinNcrankin : March 7th, 2007 at 03:45 AM.
  #4  
Old March 7th, 2007, 04:06 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Here is some INFO on PowerShadows Outbound connecting

I agree, not concerned about those outbounds at all.

Even if they were suspect PowerShadow is such a great app that I would stick with it.Too easy to block with your FW anyways.

Actually more concerned about MS apps phoning home which are blocked as well.
  #5  
Old March 8th, 2007, 12:27 PM
EASTER.2010
 
Posts: n/a
Default Re: Here is some INFO on PowerShadows Outbound connecting

Power Shadow Rocks!!!!
  #6  
Old March 8th, 2007, 08:19 PM
chew's Avatar
chew chew is offline
Frequent Poster
 
Join Date: Jun 2004
Location: GeordieLand.
Posts: 514
Default Re: Here is some INFO on PowerShadows Outbound connecting

Thanks yankinNcrankin for the info. I think I can sleep very well tonight and as I only use Windows firewall so no outbound control. As for PS it is definitely one to keep. Love it and have been playing with it for a while now. What a great find. I like it. Have you guys tested it on Limited User a/c yet?
__________________
Some men go through a forest and see no firewood.
  #7  
Old March 9th, 2007, 02:18 AM
EASTER.2010
 
Posts: n/a
Default Re: Here is some INFO on PowerShadows Outbound connecting

FWIW i never reduce my config to run on limited user, Admin all the way and safe as steel.
  #8  
Old March 9th, 2007, 08:56 AM
chew's Avatar
chew chew is offline
Frequent Poster
 
Join Date: Jun 2004
Location: GeordieLand.
Posts: 514
Default Re: Here is some INFO on PowerShadows Outbound connecting

Easter 2010, I only use Admin for Windows Update and software installation, the rest I tend to do them in my Limited User a/c. Been doing that since I found out it is "safer" to surf the net this way. But I guess if PS is on all the time that should be more than sufficient. I think I installed the copy with ADS .... damn! ;-(
__________________
Some men go through a forest and see no firewood.
  #9  
Old March 9th, 2007, 09:36 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Here is some INFO on PowerShadows Outbound connecting

My slipstreamed XP pro part SP 2 install disc is as far I will go and I won't use any MS updates in future, of which 50 odd meg are available..

If updating XP any further through MS updates it actually slows down.

And have had to ghost back to before MS's crappy updates to get my snappiness back.

Prefer my own security fixes and setup.

Running as limited user in shadowmode is like me running Sasndboxie in shadowmode.

No need but some habits are hard to break,eh.

Still much safer than running any of those "oh so great" realtime blacklist scanners!
  #10  
Old March 9th, 2007, 09:39 AM
chew's Avatar
chew chew is offline
Frequent Poster
 
Join Date: Jun 2004
Location: GeordieLand.
Posts: 514
Default Re: Here is some INFO on PowerShadows Outbound connecting

YankinNcrankin,

One question - which version is that with the INFO on PS outbound connecting?
Is that the one downloaded from PS Chinese website version 2.6 + with ADS?
Is that the one downloaded from Tuscow website version 2.6 without ADS?
Or simply version 2.82 from the PS Chinese website converted to English?................

Franklin,

Yes, imagine if I log into my Limited User a/c, run Sandboxie and all in PS ... LOL! That will be interesting.
Yes, old habit die hard. My Limited User a/c is nicely set up and I don't want to redo them in Admin ... like nice Firefox extensions ... moving pics around, documents ... etc. ...

cheers,

Chew
__________________
Some men go through a forest and see no firewood.

Last edited by chew : March 13th, 2007 at 09:13 PM.
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:15 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums