Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Monitor Sockets

Posted on 2002-06-11
9
263 Views
Last Modified: 2010-04-04
Hello,

How can I monitor ALL outing sockets from my computer,
And get:
 * what program sent the socket
 * Where to its senging
 * port of the socket
 * And The message
0
Comment
Question by:S_Warrior
9 Comments
 
LVL 12

Expert Comment

by:Lee_Nover
ID: 7071096
0
 
LVL 2

Expert Comment

by:ivobauer
ID: 7071481
Hi, listenning...
0
 
LVL 1

Expert Comment

by:barbourwill
ID: 7098437
There is a windows function called GetTcpTable which gets info on all incoming and outgiong TCP connections/connection requests and open ports.
0
Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 

Author Comment

by:S_Warrior
ID: 7153876
barbourwill:

What Unit have the GetTcpTable?
0
 
LVL 1

Expert Comment

by:barbourwill
ID: 7163247
its not in any of the delphi units, heres some of the prototypes etc:

  const
    MIB_TCP_STATE_CLOSED = 1;
    MIB_TCP_STATE_LISTEN = 2;
    MIB_TCP_STATE_SYN_SENT = 3;
    MIB_TCP_STATE_SYN_RCVD = 4;
    MIB_TCP_STATE_ESTAB = 5;
    MIB_TCP_STATE_FIN_WAIT1 = 6;
    MIB_TCP_STATE_FIN_WAIT2 = 7;
    MIB_TCP_STATE_CLOSE_WAIT = 8;
    MIB_TCP_STATE_CLOSING = 9;
    MIB_TCP_STATE_LAST_ACK = 10;
    MIB_TCP_STATE_TIME_WAIT = 11;
    MIB_TCP_STATE_DELETE_TCB = 12;

  type
    PMIB_TCPROW=^TMIB_TCPROW;
    TMIB_TCPROW = record
      dwState : LongWord; //state of the connection
      dwLocalAddr : TLongWordBytes; //address on local computer
      dwLocalPort : TLongWordBytes; //port number on local computer
      dwRemoteAddr : TLongWordBytes; //address on remote computer
      dwRemotePort : TLongWordBytes; //port number on remote computer
    end;
    PMIB_TCPTABLE=^TMIB_TCPTABLE;
    TMIB_TCPTABLE = record
      dwNumEntries : LongWord; //number of entries in the table
      table : array[0..150] of TMIB_TCPROW; //array of TCP connections
    end;

    {api declarations}
    function GetTcpTable (pTcpTable: Pointer; var pdwSize : Longword; bOrder : LongWord): LongWord;stdcall;
    function GetTcpTable; external 'iphlpapi.dll' name 'GetTcpTable';
   
0
 
LVL 1

Expert Comment

by:barbourwill
ID: 7163258
i'm not sure how you get to see the actual data being transmitted, you probably need to hook winsock or something.


0
 

Author Comment

by:S_Warrior
ID: 7236144
barbourwill:
what is TLongWordBytes?
0
 
LVL 1

Expert Comment

by:pnh73
ID: 9010517
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:

Accept answer from barbourwill

Please leave any comments here within the next seven days.
 
PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!
 
Paul (pnh73)
EE Cleanup Volunteer
0
 
LVL 6

Accepted Solution

by:
Mindphaser earned 0 total points
ID: 9102294
Force accepted, PAQ & refund
(The expert never came back for further assistance)

** Mindphaser - Community Support Moderator **
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article explains how to create forms/units independent of other forms/units object names in a delphi project. Have you ever created a form for user input in a Delphi project and then had the need to have that same form in a other Delphi proj…
In this tutorial I will show you how to use the Windows Speech API in Delphi. I will only cover basic functions such as text to speech and controlling the speed of the speech. SAPI Installation First you need to install the SAPI type library, th…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question