<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://toorcon.techpathways.com/cs/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ProDiscover Incident Response Edition </title><link>http://toorcon.techpathways.com/cs/forums/10/ShowForum.aspx</link><description>Discussions relating to ProDiscover IR functionality including finding unseen files and processes, cryptographic baselines and volatile system state information.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.0 (Build: 60217.2664)</generator><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/261.aspx</link><pubDate>Tue, 19 Aug 2008 22:29:36 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:261</guid><dc:creator>Chris</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/261.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=261</wfw:commentRss><description>&lt;P&gt;Scott,&lt;/P&gt;
&lt;P&gt;Glad to hear of the progress. Normally when the remote agent is not starting it's because of one of two things:&lt;/P&gt;
&lt;P&gt;1. Remote registry services are not running on the remote system preventing us from reading the remote sytem vars needed to set the path info in the DFTSrv.ini. You can usually confirm this by reading the dftsrv.ini located in the system32 dir of the remote system. You'll see of the full path information is missing. &lt;/P&gt;
&lt;P&gt;2. Another problem could be something preventing the application from running on the remote system. This could be anything from Permissions settings, or&amp;nbsp;MS Data Execution Prevention, to local IA tools like AntiVirus. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/260.aspx</link><pubDate>Tue, 19 Aug 2008 19:57:46 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:260</guid><dc:creator>ScottS</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/260.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=260</wfw:commentRss><description>&lt;P&gt;Chris,&lt;/P&gt;
&lt;P&gt;Thank you for your help. It seems the firewall admin "neglected" to give me both inbound and outbound access on port&amp;nbsp;6518. His boss gave me the correct access. &lt;/P&gt;
&lt;P&gt;But I also discovered that the pdserver.exe is not executing. I am using psexec to remotely execute pdser.exe.&lt;/P&gt;
&lt;P&gt;Did&amp;nbsp;I miss a step?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/259.aspx</link><pubDate>Tue, 19 Aug 2008 18:05:00 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:259</guid><dc:creator>Chris</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/259.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=259</wfw:commentRss><description>&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Scott,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri&gt;The remote agent push uses standard MS ports for file transfer as well as remote registry services and network commands to start the remote service. The remote agent port setting is strictly used after the push for agent to console communications. &lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri&gt;I’ve found the windows firewall logs helpful in determining if it blocked a connection even when off. By turning on the firewall and ensuring the firewall logging is turned on and checking the log for blocked port connection attempts. Luckily even if the service is off after logging has been turned on blocked entries are still made. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Another problem that comes to mind when people are testing is that they will try and run two remote agents on the same port at the same time, or run the console and the agent on the same system with the same port settings. This can easily happen while testing and the side effect is that only one instance/application will be able to bind to the selected port (normally the first), or that the confusion will kill that port on the IP stack of the systems being affected. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri&gt;I’ve attached the whitepaper. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/P&gt;</description></item><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/258.aspx</link><pubDate>Tue, 19 Aug 2008 17:16:05 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:258</guid><dc:creator>ScottS</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/258.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=258</wfw:commentRss><description>&lt;DIV align=left&gt;&lt;FONT face=Consolas&gt;1. you have a firewall on your computer preventing the connection back to your system. ProDiscover requires the same port to be open in both directions. So, if you have pushed the remote agent out on port 6518, then the user preferences under the file menu for PDServer needs to also be set to 6518. Likewise of you change the push settings to port 80, the user preferences also need to be set to port 80.&amp;nbsp;&lt;SPAN class=386082916-19082008&gt;&lt;FONT color=#ff0000&gt;I had our firewall admin open port 6518 and I checked the preferences for 6518.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV align=left&gt;&lt;FONT face=Consolas color=#ff0000&gt;&lt;SPAN class=386082916-19082008&gt;I also reset preferences to port 80 and pushed a new servlet. I can deploy the servlet but when I try to connect I receive this message: "Unable to connect to the remote computer-D030-00-1432739 (I tried the IP # too.)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV align=left&gt;&lt;FONT face=Consolas color=#ff0000&gt;&lt;SPAN class=386082916-19082008&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Consolas&gt;Another common issue is that most users will make sure the remote firewall settings are set to allow the port in use, but forget to turn off or set a rule on the local console firewall.&amp;nbsp;&lt;FONT color=#ff0000&gt;I&amp;nbsp;verified&amp;nbsp;that&amp;nbsp;the&amp;nbsp;local&amp;nbsp;firewall&amp;nbsp;is&amp;nbsp;off&amp;nbsp;and&amp;nbsp;the&amp;nbsp;network&amp;nbsp;firewall&amp;nbsp;allows&amp;nbsp;6518&amp;nbsp;traffic.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Consolas&gt;&lt;FONT color=#ff0000&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size=+0&gt;&lt;FONT face=Consolas&gt;We have also seen several instances where a firewall has been turned off, but in fact is still enforcing rules.&amp;nbsp;&lt;SPAN class=386082916-19082008&gt;&lt;FONT color=#ff0000&gt;How did you check for this?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Consolas&gt;I've attached a white paper with some check list that you may find helpful.&amp;nbsp;&lt;SPAN class=386082916-19082008&gt;&lt;FONT color=#ff0000&gt;I did not receive the white paper. Could you send it again?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Consolas color=#ff0000&gt;&lt;SPAN class=386082916-19082008&gt;Thanks&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;BR&gt;&lt;/DIV&gt;</description></item><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/257.aspx</link><pubDate>Mon, 18 Aug 2008 21:11:21 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:257</guid><dc:creator>Alex</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/257.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=257</wfw:commentRss><description>Scott, &lt;p&gt;

Thanks for taking the time to post to the forums.  ProDiscover uses MS file and print sharing to deploy the remote agent to the target machine.  The actual connection happens on TCP port 6518 by default.  From what you've described above it seems that packet filtering somewhere between the two computers is at fault. &lt;p&gt;

Port 6518 needs to open both inbound and outbound on both machines and at any point inbetween the 2 systems. &lt;p&gt;

Also, the Windows Firewall service is notorious for reporting that it is stopped but the service remains running. You may want to check there as well. &lt;p&gt;

Lastly, please review the forums postings below for more detailed information. Feel  free to contact me directly at: support AT techpathways DOT COM &lt;p&gt;


http://toorcon.techpathways.com/cs/forums/thread/184.aspx &lt;p&gt;


http://toorcon.techpathways.com/cs/forums/thread/8.aspx &lt;p&gt;</description></item><item><title>Re: Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/256.aspx</link><pubDate>Mon, 18 Aug 2008 21:07:35 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:256</guid><dc:creator>Chris</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/256.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=256</wfw:commentRss><description>&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;Scott,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;Looks like this could be one of a couple of issues. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;1. you have a firewall on your computer preventing the connection back to your system. ProDiscover requires the same port to be open in both directions. So, if you have pushed the remote agent out on port 6518, then the user preferences under the file menu for PDServer needs to also be set to 6518. Likewise of you change the push settings to port 80, the user preferences also need to be set to port 80. &lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;2. Another common issue is that most users will make sure the remote firewall settings are set to allow the port in use, but forget to turn off or set a rule on the local console firewall. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;We have also seen several instances where a firewall has been turned off, but in fact is still enforcing rules. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;I've attached a white paper with some checklists that you may find helpful. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;o:p&gt;&lt;FONT face=Consolas&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoPlainText&gt;&lt;FONT face=Consolas&gt;Regards, &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;</description></item><item><title>Connecting to a remote computer</title><link>http://toorcon.techpathways.com/cs/forums/thread/255.aspx</link><pubDate>Mon, 18 Aug 2008 19:16:42 GMT</pubDate><guid isPermaLink="false">e7e58421-8683-42c1-b30c-f6943a49c522:255</guid><dc:creator>ScottS</dc:creator><slash:comments>0</slash:comments><comments>http://toorcon.techpathways.com/cs/forums/thread/255.aspx</comments><wfw:commentRss>http://toorcon.techpathways.com/cs/forums/commentrss.aspx?SectionID=10&amp;PostID=255</wfw:commentRss><description>&lt;P&gt;I am unable to connect to remote computers in my Windows 2003 TCP/IP environment.&lt;/P&gt;
&lt;P&gt;I am able to push a servlet to a remote computer using port 6518 and port 80.&lt;/P&gt;
&lt;P&gt;When I try to connect, it times out.&lt;/P&gt;
&lt;P&gt;I can ping the remote machine and the firewall has been set to open port 6518.&lt;/P&gt;
&lt;P&gt;I am using a WinXP Pro&amp;nbsp;computer and trying to connect to a W2K computer sitting in the office 20 feet away from me.&lt;/P&gt;
&lt;P&gt;Any ideas would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item></channel></rss>