SunQuest
           Networking Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationNetworking Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now!
  #1  
Old June 21st, 2004, 02:49 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
detecting P2P software use on my home network?

is there a way i can detect/stop use of P2P software on my home network. We are all running win xppro machines with a netgear ADSL filewall router DG834. I can't really install software on each machine so ideally something i can do to the router or from my machine...

thanks

RF

Reply With Quote
  #2  
Old June 21st, 2004, 05:31 AM
sam the eagle sam the eagle is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 10 sam the eagle User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Open ports

Either your router has some fancy abilities or you must use your own machine as a port scanner. P2P networking software is listening on specific Ip ports ( gnutella: 6346) and if a connection is made through your gateway ( router) on this port then filesharing is very likely at hand.

Most routers i know of have the ability to do logging. This is the easiest way, and probably enough for you. Just enter the units configuration mechasism, either a web interface or terminal window, and poke around a bit. Many of these boxes can log very spesific events, but you have to tell it to do so first.

When you get an overlook on the ports you do not want treffic on, you can simply block those in the router.

Reply With Quote
  #3  
Old June 21st, 2004, 05:31 AM
Rizla's Avatar
Rizla Rizla is offline
fifo
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2003
Location: Canvas3D()
Posts: 240 Rizla User rank is Sergeant (500 - 2000 Reputation Level)Rizla User rank is Sergeant (500 - 2000 Reputation Level)Rizla User rank is Sergeant (500 - 2000 Reputation Level)Rizla User rank is Sergeant (500 - 2000 Reputation Level)Rizla User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 20 h 6 m 12 sec
Reputation Power: 13
Two ways i can think of:
Either you could block the range of ports that the file sharing program uses from your router. Although programs like kazaa and soulseek allow you to change the port it uses so any one with some knowledge of the app will just change it. Alternativly you could install a firewall such as mcafee or norton and block the file sharing program's access to the internet. As long as you set an admin password for the firewall, the program couldn't get access.
__________________
Never trust a man who, when left alone in a room with a tea cosy, doesn't try it on. - Billy Connolly

Reply With Quote
  #4  
Old June 21st, 2004, 05:44 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
hi there, thanks for both of those suggestions. I currenlty am using zonealarm but i have not admin passworded it. I like the idea of logging, i think that would be a good place to start as if i have proof it is there then i can take measures to stop it.

I have included a screen shot of a page of the admin control of my router....could i use something like this to block the port? then i assume it would come up in the log as an Attempted access to blocked sites....am i along the right lines here....

thanks very much for your replies..

RF

Reply With Quote
  #5  
Old June 21st, 2004, 06:30 AM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 36 m 40 sec
Reputation Power: 92
Just to bump in here, but it is possible to stop certain programs being run from within Windows. I don't think this is really what you want, since you want to log activity, but if you launch gpedit.msc from the Run dialog box, you'll find a setting in there where you can enter exe file names and these will be restricted, so that whenever someone trys to run the program, they get an access denied error message. This is a pretty easy way to stop the programs being run, as long as you know the exe file names.
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
  #6  
Old June 21st, 2004, 08:32 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
thanks edwin, but would the user just not be able to undo that??

port scanning was mentioned...what software would anyone recommend for this... i remember port scanning being discussed at uni but i dont remember any programs being suggested..

thanks

RF

Reply With Quote
  #7  
Old June 21st, 2004, 09:28 AM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 36 m 40 sec
Reputation Power: 92
Quote:
Originally Posted by RadioactiveFrog
thanks edwin, but would the user just not be able to undo that??


yeah, I suppose so! Depends how good on computers they are. There are programs you can get though which offer similar functions to the gpedit.msc which can be applied only to certain users and cannot be changed by normal users.

Reply With Quote
  #8  
Old June 21st, 2004, 12:36 PM
sam the eagle sam the eagle is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 10 sam the eagle User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Smile Logging.

From the attachment a few posts ago it looks like you can do some logging. And there is a button for services, and one for firewall rules. Firewall rules go on top of the default policy by the way. So if the default is to block every incoming request, you could still add a rule that allows port 80 to inside adress 1.2.3.4 or whatever.

Perhaps a search on Google for known ports, and a search for different p2p programs would be yor next step. Write down what ports the different programs use, and make rules to silently drop all of those packets, inbound or outbound.

Be careful not to muck things up for messenger services, most people like to have those things on. This is not an easy task if you are new to ethernet an TCP-IP , and many network admins spend a lot (but not enough) of time with stuff like this.

Here are a few links to help you on the way. Find your way through the jungle and see the light ).

http://www.protocols.com/pbook/tcpip1.htm
http://www.iana.org/assignments/port-numbers

PS. There is an app called Ethereal, wich will tell you a lot about the packets on your lan. I do not know if it runs on windows though.

Reply With Quote
  #9  
Old June 21st, 2004, 12:48 PM
SgtFirewall SgtFirewall is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: San Antonio
Posts: 23 SgtFirewall User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 12 h 48 m 19 sec
Reputation Power: 0
Send a message via ICQ to SgtFirewall
Ethereal is available for windows. You'll have to download and install WinPCAP as well to get Ethereal working (active packet captures).

http://www.ethereal.com/distribution/win32/

http://winpcap.polito.it/install/default.htm

Reply With Quote
  #10  
Old June 22nd, 2004, 02:30 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1Folding Points: 155419 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
hello all, thanks for the replies, i have tried putting the limewire port and a few others as services...i am assuming this will prevent access to them!! I have done a search for the ports of the big P2P software..

thanks for the software links, i am going to try port scanning the computer later today.

Cheers

RF

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationNetworking Help > detecting P2P software use on my home network?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |