PDA

View Full Version : P2P Detection



Lord_Foul
01-23-2005, 12:31 AM
Hi,

Question:
Is there an accurate way to identify a user/ip address within a LAN who is using P2P software such as emule, winmx or Bitorrent etc. using free software tools?

I can use ethereal in promiscuous mode to monitor internal traffic and then look for default udp/tcp ports i.e 4662, 4672 etc. The problem here is that the ports can easily be changed via the P2P client. I have found some software that claims it will work, but it is prohibitively expensive and so is not an option.

The LAN has a firewall and proxy server, but im sure the user is an admin and has enabled a rule allowing P2P in/out and is also probably bypassing the proxy server, i don't want to raise his suspicions as he is a good friend, i'd just like to startle him with proof heh.

I pretty sure that P2P traffic from the different networks have unique signatures, but i have no idea how to identify these sigs from a network capture. Maybe i have to drill-down into the packets and have a deeper look but it is a busy network and will take forever.

Any advice or help much appreciated.

SyntaXmasteR
01-23-2005, 02:20 AM
I just wrote up a little program just for you :-) All you have to know is one file associated with each program that you suspect he is downloading. Email me at syntax******@hotmail.com and ill send you the prog. You are an admin on the network right?

Lord_Foul
01-23-2005, 05:18 AM
SyntaX******,

Yes i am an admin also, i run the Server Team (O/S, e-mail, AD etc.)

I have sent you my e-mail address...

Incidentally, i stumbled accross this site last night, then ended up spending 2-* hours reading hundreds of posts. Your willingness to help people from all ********* levels is admirable - it's re*****ing to see...you quite obviously have a impressive level of knowledge in this field, thank you for unselfishly sharing your expertise with people.
Sorry if that made you blush, but it needed saying!

SyntaXmasteR
01-23-2005, 10:22 AM
I appreciate the complement Lord_Foul

The way i look at it: Everyone starts somewhere right? I've read too many forums where the supposedly "More Skilled" and "Higher Ups" critisize every question without answering them. How do you learn when someone does that? Hope i can share my knowlege with whomever is willing to listen.

SyntaXmasteR
01-23-2005, 04:04 PM
I have emailed you the program -