Go Back   Phoenix Labs > Security > Guides
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes

 
Old 01-25-2006, 10:21 PM   #1
r00ted
 
r00ted's Avatar

Retired/On Leave
Join Date: Sep 2005
Country: United States
Posts: 6,849
Default Guide: Posting Pg2 Logs

First, images are evil. Please do not post your pg2 logs in image(png/bmp/jpg/etc) format. When investigating a log, it is nice to be able to copy and paste the content.

So, here's how.

Open up Pg2. Either by launching the Pg2.exe, or clicking on the tray icon.
Click the "View History" button. Depending on your RAM/cpu, and overall log size, this may take a second or five.
You will be presented with the History window:


From here, click the File menu, and move down to Export to.

Upon clicking Export to, you will be presented with another dialog box:


The To: and From: fields should be ticked/checked/enabled, and set to one day. Chances are, if you have a question regarding a log entry, it's going to be from Today, maybe yesterday, so set those dates, so they are the same.

By doing this, you will only generate one days' worth of logs.

You can keep the Protocol field disabled. By disabling that field, the exported logs will contain all traffic, no matter what protocol was used.

The Action field should be set to "Blocked" so that only Blocked connections are exported. Of course, if you have a question regarding a packet that snuck past, you would set this field to Allowed.

The output file field can really be anywhere, but I find it easiest to export to my desktop, so I can find it easily.

You are all set up, click the OK button, and go get a drink, bathroom break, or whatever :P Depending on how big your history.db file is. Just for reference, my history.db file is 275 MB (288,899,072 bytes) :) And it only took about 5 seconds to generate. But I have not done any p2ping today. Days where I was p2ping, it took much longer to generate the daily log exports of blocked connections.

So anyways, now you should have the exported file wherever you saved it. Open the file, and find the connection you were questioning. You can use your Notepad-Find skills to lookup the IP or company name you saw blocked, and just copy the entries from within the log file. It is easiest for us to investigate logs if you have clearly noted the IPs/connections you have questions regarding ;)

Anyways, that's about it. This guide should be sufficient unless the pg2 dialog boxes are re-designed.

Any questions regarding this tutorial/guide, feel free to reply. IP address or IP Investigation questions should be directed to the proper forum, and NOT as a reply here.

UPDATE!
I've been asked via PM, how to "Export" or "Archive" pg2 logs without using the auto-generated/archive feature in the pg2..since there seems to be a bug with it duplicating logs/data, and well, not giving time stamps..so...you basically follow these similar steps except the part where you "Export to"...you will set your options like so:



When you hit OK, ALL available data will be exported.

It's as simple as that ;)

*All images within are thumbnailed, single left-click the image to see a bigger/clearer image*

Last edited by r00ted : 03-22-2006 at 04:09 PM. Reason: typos, thx kidcash
r00ted is offline   Reply With Quote

 
Old 01-25-2006, 11:57 PM   #2
kidcash
 
kidcash's Avatar

Cooler Master
Join Date: Feb 2005
Location: Australia
Country: Australia
Posts: 3,170
Send a message via AIM to kidcash Send a message via MSN to kidcash Send a message via Yahoo to kidcash
Send a message via Yahoo to kidcash
Default Re: Guide: Posting Pg2 Logs

Quote:
Originally Posted by r00ted
Upon clicking Extract to,
Correction : Export
Heh i sorta got confused when i found no Extract in the menu

Otherwise its a really nice guide, Images are evil.
The same log in text form will load upto 20 times faster than an image ;)

I think the forum rules should be updated , The agreemend before you signup.
Or maybe a sticky thread should be made called "Posting rules" that contains all the rules or something
__________________
Need Help? Contact Me : MSN - vl.turbo.88@gmail.com, AIM - k1dcash Yahoo - Kidcash5000 Email : vl.turbo.88@gmail.com




Last edited by kidcash : 01-26-2006 at 12:06 AM.
kidcash is offline   Reply With Quote

 
Old 01-26-2006, 12:17 AM   #3
winMX_67
 
winMX_67's Avatar

L337 Poster
Join Date: Sep 2005
Country: United States
Posts: 1,422
Default Re: Guide: Posting Pg2 Logs

Thanks r00ted. Next time I connect to ares ill post tbe blocks that occur at start up. It takes forever to connect when PG2 keeps blocking the connections.
__________________









To the MPAA and RIAA: Don’t wound what you can’t kill.
winMX_67 is offline   Reply With Quote

 
Old 01-26-2006, 02:19 AM   #4
r00ted
 
r00ted's Avatar

Retired/On Leave
Join Date: Sep 2005
Country: United States
Posts: 6,849
Default Re: Guide: Posting Pg2 Logs

exactly. at first i was recommending users post images, but it is a pain to hand type IP addresses to whois, and then make sure they are typed correctly etc :P so i figured I'd make this little tutorial :)
r00ted is offline   Reply With Quote

 
Old 01-26-2006, 02:24 AM   #5
r00ted
 
r00ted's Avatar

Retired/On Leave
Join Date: Sep 2005
Country: United States
Posts: 6,849
Default Re: Guide: Posting Pg2 Logs

Quote:
Originally Posted by kidcash
Correction : Export
Heh i sorta got confused when i found no Extract in the menu
oops. thx, fixed.
r00ted is offline   Reply With Quote

 
Old 02-27-2006, 02:29 PM   #6
fox
 
fox's Avatar

Infringement Specialist
Join Date: Sep 2005
Location: In your momma's house.
Country: Canada
Posts: 2,822
Send a message via ICQ to fox Send a message via AIM to fox Send a message via MSN to fox
Donor
Default Re: Guide: Posting Pg2 Logs

hey r00ted. i posted this guide on the phoenixlabs beta documentation page http://wiki.phoenixlabs.org/

Last edited by fox : 11-14-2006 at 09:06 AM. Reason: url updates
fox is offline   Reply With Quote

 
Old 02-27-2006, 05:50 PM   #7
Unplugged
 
Unplugged's Avatar

Junior Member
Join Date: Feb 2006
Posts: 2
Default Re: Guide: Posting Pg2 Logs

What´s the site? I tryed but didnt found anything..
thx!

Ok, I will take a look! thx a lot!

Last edited by Unplugged : 02-27-2006 at 05:54 PM.
Unplugged is offline   Reply With Quote

 
Old 02-27-2006, 05:53 PM   #8
fox
 
fox's Avatar

Infringement Specialist
Join Date: Sep 2005
Location: In your momma's house.
Country: Canada
Posts: 2,822
Send a message via ICQ to fox Send a message via AIM to fox Send a message via MSN to fox
Donor
Default Re: Guide: Posting Pg2 Logs

it is beta and not available yet. http://wiki.phoenixlabs.org/wiki/Main_Pagethats where it will go.

just stay posted and check there everyday.
fox is offline   Reply With Quote

 
Old 02-27-2006, 05:57 PM   #9
Unplugged
 
Unplugged's Avatar

Junior Member
Join Date: Feb 2006
Posts: 2
Default Re: Guide: Posting Pg2 Logs

anyway.. is that something serious going on here?
Unplugged is offline   Reply With Quote

 
Old 02-27-2006, 06:36 PM   #10
winMX_67
 
winMX_67's Avatar

L337 Poster
Join Date: Sep 2005
Country: United States
Posts: 1,422
Default Re: Guide: Posting Pg2 Logs

unplugged, you are getting ghost packets, the tracker hasnt let your IP go. Search ghost packet(s) on the forum.
__________________









To the MPAA and RIAA: Don’t wound what you can’t kill.
winMX_67 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HowTo: Compress PG2 archive logs using WinRar bbb_uk Guides 31 01-16-2006 01:59 AM
The Hitchhikers Guide to the Galaxy is back! JFM General Discussion 4 07-28-2004 06:47 AM


All times are GMT -5. The time now is 06:39 AM.


  

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© Phoenix Labs Staff