Solved

Monitor Sockets

Posted on 2002-06-11
9
259 Views
Last Modified: 2010-04-04
Hello,

How can I monitor ALL outing sockets from my computer,
And get:
 * what program sent the socket
 * Where to its senging
 * port of the socket
 * And The message
0
Comment
Question by:S_Warrior
9 Comments
 
LVL 12

Expert Comment

by:Lee_Nover
ID: 7071096
0
 
LVL 2

Expert Comment

by:ivobauer
ID: 7071481
Hi, listenning...
0
 
LVL 1

Expert Comment

by:barbourwill
ID: 7098437
There is a windows function called GetTcpTable which gets info on all incoming and outgiong TCP connections/connection requests and open ports.
0
 

Author Comment

by:S_Warrior
ID: 7153876
barbourwill:

What Unit have the GetTcpTable?
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 1

Expert Comment

by:barbourwill
ID: 7163247
its not in any of the delphi units, heres some of the prototypes etc:

  const
    MIB_TCP_STATE_CLOSED = 1;
    MIB_TCP_STATE_LISTEN = 2;
    MIB_TCP_STATE_SYN_SENT = 3;
    MIB_TCP_STATE_SYN_RCVD = 4;
    MIB_TCP_STATE_ESTAB = 5;
    MIB_TCP_STATE_FIN_WAIT1 = 6;
    MIB_TCP_STATE_FIN_WAIT2 = 7;
    MIB_TCP_STATE_CLOSE_WAIT = 8;
    MIB_TCP_STATE_CLOSING = 9;
    MIB_TCP_STATE_LAST_ACK = 10;
    MIB_TCP_STATE_TIME_WAIT = 11;
    MIB_TCP_STATE_DELETE_TCB = 12;

  type
    PMIB_TCPROW=^TMIB_TCPROW;
    TMIB_TCPROW = record
      dwState : LongWord; //state of the connection
      dwLocalAddr : TLongWordBytes; //address on local computer
      dwLocalPort : TLongWordBytes; //port number on local computer
      dwRemoteAddr : TLongWordBytes; //address on remote computer
      dwRemotePort : TLongWordBytes; //port number on remote computer
    end;
    PMIB_TCPTABLE=^TMIB_TCPTABLE;
    TMIB_TCPTABLE = record
      dwNumEntries : LongWord; //number of entries in the table
      table : array[0..150] of TMIB_TCPROW; //array of TCP connections
    end;

    {api declarations}
    function GetTcpTable (pTcpTable: Pointer; var pdwSize : Longword; bOrder : LongWord): LongWord;stdcall;
    function GetTcpTable; external 'iphlpapi.dll' name 'GetTcpTable';
   
0
 
LVL 1

Expert Comment

by:barbourwill
ID: 7163258
i'm not sure how you get to see the actual data being transmitted, you probably need to hook winsock or something.


0
 

Author Comment

by:S_Warrior
ID: 7236144
barbourwill:
what is TLongWordBytes?
0
 
LVL 1

Expert Comment

by:pnh73
ID: 9010517
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:

Accept answer from barbourwill

Please leave any comments here within the next seven days.
 
PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!
 
Paul (pnh73)
EE Cleanup Volunteer
0
 
LVL 6

Accepted Solution

by:
Mindphaser earned 0 total points
ID: 9102294
Force accepted, PAQ & refund
(The expert never came back for further assistance)

** Mindphaser - Community Support Moderator **
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Introduction The parallel port is a very commonly known port, it was widely used to connect a printer to the PC, if you look at the back of your computer, for those who don't have newer computers, there will be a port with 25 pins and a small print…
Hello everybody This Article will show you how to validate number with TEdit control, What's the TEdit control? TEdit is a standard Windows edit control on a form, it allows to user to write, read and copy/paste single line of text. Usua…
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now