Forum Replies Created
-
AuthorPosts
-
December 6, 2007 at 6:50 am in reply to: what’s the time to release new version for winpkfilter #6483
That’t Right!
hope 3.0.4 can release early.
some questions:
1. if i am a license buyer,can we get the both x86 and x64 current version?
2.can u get me some examples at lease two which use winpkfilter for himself software?
3.a fool question ๐ ,it is: if i but the winpkfilter for a license,when i send my software which used the winpkfilter, ~~~~~~this’s to say: the winpktilter driver i paid will be published. how to prevent it? ๐ ๐ ๐ฏ ๐ฏ(software+winpkfilert(licensed))
>other will be used it
>other get the winpkfilert(licensed). all right?do u have email. i want to ask something about how to buy it~~ ๐
many thanks!!!!!!!!!!
@alex_s wrote:
Anybody has the ideas on how to resist ARP spoofing aside from:
“to drop any requests from” and “to drop any replies to” the addresses other than gateway address. The problem is in case LAN is already spoofed it can be tricky to define gateway’s mac address.
i think we can wait the new version together~ ๐
November 21, 2007 at 1:36 pm in reply to: what’s the time to release new version for winpkfilter #6481please,what’is the time for release the new version.
the flowers had been droped.. ๐ฅ ๐ฅ ๐
November 10, 2007 at 4:48 am in reply to: what’s the time to release new version for winpkfilter #6480@SerpentFly wrote:
SendFlagTcpPacketToTcp(Lastpacket,Flag,fromip,toip,from port,toport);
It would also need SEQ and ACK. Basically you can write such a function using the existing API completely in user mode.
oh~~~aha~maybe sorry for my poor Porgrame skill.
i beg u write out a delphi code for send such code use winpkfilter api.even if it is a send rst packet!i can not,yes,i did can not get any message for the examples~
November 9, 2007 at 1:54 pm in reply to: what’s the time to release new version for winpkfilter #6478Great!
if you want to test please contract me from bbs message. ๐
about the send rst packet,it is very important.
we known,the firewall’s important point is protect the host. if we deny the bad ip from the host,for the first time,we will see the host remain a port state:Time_wait.if we deny many and many ip,the host we get over of the States.
Then like Time_wait, the windows system will keep it for 20 minuts at last.
i suggest add one api for winpkfilter. the api can send any Tcp flag packet. by pass in last tcp packet and tcp flag,we can get the buffer. at last,we can send this packet.
eg:
SendFlagTcpPacketToTcp(Lastpacket,Flag,fromip,toip,from port,toport);just a sample.
and eg: sendFlagTcppacketToadpatch……
by the way,how to get the IFS HOOK like winpktilter(NDIS HOOK)?
reguards!!!!:)
๐ ๐
i means i hope 3.0.4’s winpkfilter could add more characteristic.
eg: filterinfo or get the packet easy to deal with, after all,many time people are deal with the tcppacket. so How convenient!!!! like checksum,psdtcpheader๏ผwinpkfilter can give a temple structure. then not so much people will ask more question like “how to send a raw packet?” etc~~
best reguard~~ ๐ ๐
good!hope the next version~can u give a release time?
byt the way. i did not send out a packet by winpkfilter. 3.0.4 need more Characteristic property for firewall secion. let more things done in ring0 Automationly
@Deneb wrote:
Hello,
we need a mechanism to detect ( and prevent ) a process from opening a web page using the IWebBrowser / IWebBrowser2 interface via Internet Explorer. It is unclear if we should ( or can ) hook the CoCreateInstance or the methods inside the interface. A preferable method would be to hook the COM server for this interface as I suspect the server is a standalone process. Can anyone help me in this direction?
Thanks
do u have a result for you question? u can exchange with me: iisfirewall@126.com
good!
and….~
need to be chechsum or is it will be do the checksum by the SendPacketToMstcp or SendPacketToAdapter?by the way,if i want to close the connection,need i send send a rst packet to both MSTCP and Adapter?
how to do it (rst packet)?
3ks for your best~
hi~
Thx very Much!and~~…
because u had said:my app work in usermode. i want t deal with every packet, but it is still will be done in usermode not in the ring0.
please tell me System efficiency can Affected much more?
3ks for your exciting answer
on the other hand,:) if my net traffice reach on 7mbps,can cause lose packet?may be!
i love pkfilter!you are good author!!
by the way,when i use pkfilter, i found you alloc 1534 bytes for everypacket,why not 1514?? ๐
-
AuthorPosts