Security Basics mailing list archives

Re: analysing network activity of processes on my pc


From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Wed, 15 Nov 2006 23:58:11 +0100

On 2006-11-15 sami seclist wrote:
I would like to monitor and analyse network taffic generated by
processes on my win box.
I first used wireshark (fomerly ethereal), but it doesn't map trafic
to processes, while TDImon from sysinternals gives me this information
because it seems to monitor system calls.however this tool has limited
features in its free version, it simply lists all calls (dozens by
seconds which makes it unpractical).

So Does any of the members of this list knows of a free tool
(preferably open source) that could do the job, and if not do u
suggest another way to do what I want ?

Try Port Reporter [1]. It doesn't inspect the traffic, though. For that
you'd still need Wireshark or something similar.

[1] http://support.microsoft.com/kb/837243

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: