Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 23rd, 2003, 12:43 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default ProPort v 2.2

I am trying out ProPort at last and am not sure why, but there is no help file and the website is down for reconstruction. The other things that is wierd is the attack log is not displayed after you shut down ProProt and restart it again.
the first two attacks were recorded with Sygate not running.
Shivka-burka
Scarab

the last attack was captured with Sygate running again

Fake FTP
Attached Images
 
  #2  
Old February 23rd, 2003, 04:59 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

Most recent attack log..

see TXT file.
Attached Files
File Type: txt AttackReport1.txt (2.5 KB, 0 views)
  #3  
Old February 23rd, 2003, 07:48 PM
eyespy's Avatar
eyespy eyespy is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Oh Canada !!
Posts: 490
Default Re:ProPort v 2.2

Controler,
these are possibe trojan scans...correct ?
And whats with that loopback being possible Fake FTP ??

regards,
bill
__________________
bill

"When you come to a fork in the road....Take it" ("Yogi" Berra )
  #4  
Old February 23rd, 2003, 08:40 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

eyespy

I am not real sure what this program is all about yet but it looks like it has good potential. The start-up editor seems to need some serious work though. I will be gone all next week for work and won't get much time to mees with it. Have you tried it out yet eyespy?
Not sure what the loopback alert was all about yet either.


  #5  
Old February 23rd, 2003, 10:59 PM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,523
Default Re:ProPort v 2.2

It appears that the program is hooked into the network stack somehow, and it is monitoring for any activity to a set of "known trojan" ports. If there is any activity at all on a monitored port, then the relevant data is written to the attack log with the guess that it could be the known trojan listed.

Now, it also appears that it is not differentiating between the different network interfaces on your system. The localhost activity (127.0.0.1) is being reported the same way as your actual public (Internet) interface, when all it is likely to be is just simple loopback access to some randomly assigned return port for some network aware application.

It looks like an interesting tool, especially if you were using a firewall that had limited alert or logging capability, or if you wanted the firewall's logging disabled, but, wanted to monitor for this type of activity.

Does it allow you to add and remove ports from the list it is monitoring? That could be very useful.
  #6  
Old February 24th, 2003, 08:34 AM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

Hi LowWaterMark


The program is wirtten in machine language and is fast. It is only an exe file and doesn't actualy install.
Sine I am so hard pressed for time this week and won't be back till Friday I just have enough time to post the screen shot where you can add your own ports.
I was hoping you guys would get a chance to check it out
Have a nice week

Attached Images
 
  #7  
Old March 1st, 2003, 02:12 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

After messing around with this program a bit more this weekend, I see it has a link to a page with various info. Some is good, such as how to make your firewall more trojan resistant (link removed) but some of the info is on how to write perl viri ect. Both English and German instructions. You be da judge.

Their program link is to a forum with only ONE member ans not much else.

(tutorial link removed)



- You were right controler when you said "some of the info is on how to write perl viri...". That being instructions on how to right better malware, the links have been removed.
  #8  
Old March 1st, 2003, 03:32 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:ProPort v 2.2

Quote:
After messing around with this program a bit more this weekend, I see it has a link to a page with various info.

Well well...Eric seems to be alive and kicking. FYI: this guy created the "old" TFAK .

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #9  
Old March 2nd, 2003, 12:54 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

There appears to be some new information posted at his website.
Has he been invited to post here yet?
I think he is too busy to answer private e-mails about his product.

http://www.tdupage.com/
  #10  
Old March 3rd, 2003, 10:22 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:ProPort v 2.2

At first I thought this product had potential.
I have now changed my mind and am abandoning and removing all traces of this software from my system due to suspicions about the creators intentions on the internet.
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:49 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums