How can I log the process id associated to a local socket blocked by the PF firewall?

Hi,
There seem to be a problem with mac OSX PF firewall logging capabilities.
I am trying to find the process id associated with a connection attempt blocked by PF. I am replicating, in a way, the feature found in a commercial firewall caled "Little Snitch"
This is the method I have tried so far:
1- I wrote a new pf config file with a ruleset that blocks all outbound connection attempts and logs it (see my ruleset at the bottom)
2- I create the pflog0 interface
sudo ifconfig pflog0 create
3- I load the new pf config file
sudo pfctl -d && sudo pfctl -f ./mypf.conf && sudo pfctl -e
4- I log the blocked packet and try to retrieve the process names
sudo tcpdump -n -e -vvv -ttt -i pflog0 > mypf.log
OR
sudo tcpdump -n -s0 -w ./mypf.pcap
Either way, none of my "mypf.log" or "mypf.pcap" files contains any information about the processes.
Any idea how I could log the PID of the processes?
##my ruleset mypf.conf
##MACRO
host_if = "en0"
##OPTIONS
set loginterface $host_if
set debug misc
set skip on lo
##RULES
#I dont want to log all incomming connection, I just want to block it by default
block in all
#I want to log all attempts from processes to establish a connection outside
block out log (user) all

Hmmm....
Your story is familiar - many folks here are somewhat bewildered by the
technology that keeps coming up in their faces when they think that this
process should be a simple one.  It SHOULD be, but....
SONY Reader software for your PC is designed to 'captivate' you so that
your ereader will function well with their store.  It is, in essence, their
way of managing your elibrary.  And it's proprietary to SONY.   You can add
ebooks to it in a similar way that you can add them to ADE.  Since we're an
ADE forum, I don't have those steps in my reference file - sorry.
As you've explained it, DRM protection is really not the issue here.  ADE's
way of managing the relationship between you and the ebook is to keep track
of who did the original download in a small ID file embedded in the ebook.
ADE is telling you that your husband downloaded the ebook in question, and
that you're not able to read it with your own ID.  The SONY message is
essentially the same thing, but in different and confusing wording, which
makes you believe that DRM protection is getting in your way.  That's
probably not true, because you're not getting a 'No Permission To Copy
Here' message from ADE - their way of telling you that the digital rights
assigned by the publisher, distributor or author will prevent you from
making a copy.  Shame on SONY for confusing the issue!
What you can try is to deauthorize ADE by using the CNTLSHIFTD keys
together after it opens and is waiting for you to do something.  Then,
close ADE.  When you reopen ADE, it will ask you to authorize it, and you
can put your husband's ID in.  ADE now thinks you are your husband, and
will let you access all of his ebooks.  You can copy them to your ereader
at this point and then open them to read - assuming that there really is no
DRM protection that prohibits the copy.
There's more, but let's take this one step at a time, eh?
================

Similar Messages

  • How can I log the data transmission of my switch in a file to analyze the quality of my communication channel?

    How can I log the data transmission of my switch in a file to analyze the quality of my communication channels?

    A lot depends on what type of switch you have and what kind of communication channels you're asking about.
    There are several Cisco tools (e.g., "ip sla", SNMP-queried values, show commands etc.) that can give useful information.
    If you give us some more information we can help more specifically.

  • How can I log the byte count for a network interface

    I'd like to track/log the number bytes transmitted and received on a network interface. The end result is to give daily and or monthly usage counts.
    How can I do that?

    This software might do the trick. Not too expensive and it has a free trial.
    It keeps logs of each time the program is run and you can configure it to run at system startup in the preferences window. If you go to the Tools menu and choose Traffic Log the calculator can let you specify time frames. Might be what you need!
    http://www.macupdate.com/info.php/id/6172/net-monitor
    -Pat

  • How can I log the WebService-http stack in JDK

    I have a WebService server in jdk (no applicationserver)
    I have a class with @Webservice and publish it with EndPoint.publish(...
    My users sometimes gets "500 bad request" or something when they make calls with invalid http or xml.
    How can I make java to log this? I want to see in my log when a user send a invalid call, and how the call looked like.
    How do I turn on the logging and direct it in a file. java.util.logging? Which classes? Anyone that have a good config-file for this?

    well for starters, doing "com.sun.xml.ws.transport.http.HttpAdapter.dump = true;" will cause the raw http information to be dumped to stdout.

  • How can I log the webdav

    My server is 9ias9.0.2 + 9ifs9.0.2 on w2k. I want to see the logs when I run the webdav. Can you tell me which kind of commands are needed to set up the logs on webdav?
    Thank you in advance for your time and your helps.

    Thank you for your suggestion. It truely does work. What I want to know is something like below. My OS is win2000, application server is 9ias9.0.2 and 9ifs9.0.2. Your advice is highly appreciated.
    sample:
    i've set the following parameter in
    "../Apache/Jserv/etc/ifsprops.properties":
    # Arguments passed to Java interpreter (optional)
    # Syntax: wrapper.bin.parameters=[parameters] (String)
    # Default: NONE
    wrapper.bin.parameters=-DIFS_DAV_DEBUG=true
    Then i'restart the whole 9iFS with:
    ifsJservctl -stop
    ifsstopdomain
    apachectl stop
    apachectl start
    ifslaunchdc
    ifslaunchnode
    ifsstartdomain
    ifsJservctl -start
    jserv.log:
    [22/11/2001 00:31:13:194 GMT+01:00] <debug> - Using
    configuration file:
    /opt/oracle/product/o9i/Apache/Jserv/etc/ifs.properties
    [22/11/2001 00:31:13:342 GMT+01:00] <debug> Creating new sessions
    hashtable.
    [22/11/2001 00:31:14:346 GMT+01:00] <servletLog>
    files/oracle.ifs.protocols.dav.impl.IfsDavServlet: init
    [22/11/2001 00:31:14:793 GMT+01:00] <servletLog>
    files/oracle.ifs.protocols.dav.impl.IfsDavServlet: NodeGuardian:
    [22/11/2001 00:31:14:795 GMT+01:00] <servletLog>
    files/oracle.ifs.protocols.dav.impl.IfsDavServlet: NodeGuardian:
    Oracle Internet File System
    [22/11/2001 00:31:14:799 GMT+01:00] <servletLog>
    files/oracle.ifs.protocols.dav.impl.IfsDavServlet: NodeGuardian:

  • How can i disable the SPI Firewall built in my WRT54G Ver.5?

    plz help, guys!!!

    There is no way to disable this firewall. If you need to open any particular traffic out of this router then you can go port forwarding, port triggering or DMZ, depending upon your requirement. If you have any specific requirements revert back.

  • How can I log ad System?

    I installed OS X and I get logged as Admin. To cancel any apps or to unlock the System Preferences I need to be logged as System. How do I do that?
    Thanks.

    There are NT service "shell" utilities that allow Weblogic to be run "as a
    service", and you need to consult the documentation per each to determine
    how to capture std out / err.
    Peace,
    Cameron Purdy
    Tangosol Inc.
    << Tangosol Server: How Weblogic applications are customized >>
    << Download now from http://www.tangosol.com/download.jsp >>
    "Poe Lam" <[email protected]> wrote in message
    news:3b95d59b$[email protected]..
    >
    But if my weblogic is running in service, how can i log the std err?
    "Cameron Purdy" <[email protected]> wrote:
    Typically to capture std out you use '>' and to capture std err you use
    '>2'
    instead so you can send both to a single log file on most OSs.
    Peace,
    Cameron Purdy
    Tangosol Inc.
    << Tangosol Server: How Weblogic applications are customized >>
    << Download now from http://www.tangosol.com/download.jsp >>
    "Poe Lam" <[email protected]> wrote in message
    news:3b8f35ee$[email protected]..
    Hi all,
    I would like to ask how can i log System.err to weblogic.log, is itpossible?
    and how?
    I'm using version 5.1
    Thank you very much
    Poe

  • How can I change the email associated with my forum account?

    How can I change the email associated with my forum account?  I didn't provide my work email to you, but you put it in my account.  My forum postings have nothing to do with my personal PC at home.  There isn't an option to update it.
    This question was solved.
    View Solution.

    Hi:
    Log in and click on your user name, then look at the upper the right side of the page.
    Click on the triangle to the left of the "More Resources" section.
    This will drop down, and give you options.
    Select User Settings.
    This will now open a page, and in the light blue type on top, follow it along to Contact Information, click on that, and change your e-mail address to what you want, and hit the blue submit button on the bottom right side of the page.
    Paul

  • I have 2 iphones, one for personal and one for business.  I need my phones not to sync otherwise they will both ring all the time.  How can I log out of my icloud and unsync my phones?

    I have 2 iphones, one for personal and one for business.  I need my phones not to sync otherwise they will both ring all the time.  How can I log out of my icloud and unsync my phones?

    Syncing your phones to the same iCloud account won't cause them to both ring all the time, it only puts the same contacts, calendars, and other synced data on the phone.  The phones will only ring with someone calls the number associated with the phone.
    If you want to stop using iCloud on one or both of the phones, go to Settings>iCloud, tap Delete Account, then choose Keep On My iPhone when prompted.  This will disconnect them from iCloud and keep a copy of the synced data on the phone.

  • How can u know the process chain total time, individual time?

    Hi guru's
    How can u know the process chain total time, individual time?
    and what options will available in sm37?
    Thanks
    prabha reddy

    Hi Prabha
    Iam not very sure about total time and individual times.
    But you can go to tcode rspcm for monitoring the daily process chains. it gives you details like 1. status  2.start date & time  3. Log ID  of each process chain.
    or you can go to log view of particular individual chain to know how long it has run.
    SM37: tcode for simple job selection.
    here you check the status of job.
    you can select for certain conditions like
    1. scheduled
    2. released
    3. ready
    4.active
    5. cancelled
    Assign points if it was helpful
    Revert back if you need further info/
    regards
    AP

  • How Can I record the user's logging time?

    How Can I record the user's login time?I create a table containing some column such as record_id,username,start_time,end_time,period.How can I create a process on logging in to record the start_time and a process on logging out to record the end_time?
    Thanks for any help.

    you can refer to the name of the currently logged in user using :APP_USER. to capture the login info, i'd add an htmldb process to my app that fired "After Authentication" and simply inserted :APP_USER and sysdate into my logging table. for the logout case, you could change the "Logout URL" of your current authentication scheme to one that does whatever it's currently doing plus the logging. so i Logout URL of...
    wwv_flow_custom_auth_std.logout?p_this_flow=&APP_ID.&p_next_flow_page_sess=&APP_ID.:101:&APP_SESSION.
    ...and i changed it to something like...
    my_schema_name.my_logout?p_user=&APP_USER.&p_app=&APP_ID.&p_session=&APP_SESSION.
    ...where my_logout was...
    create or replace procedure my_logout(
    p_user in varchar2,
    p_app in varchar2,
    p_session in varchar2) as
    begin
    insert into my_logging_table values (sysdate, 'logged out as '||p_user);
    wwv_flow_custom_auth_std.logout (
    p_this_flow => p_app ,
    p_next_flow_page_sess => p_app||':101');
    end;
    ...and things worked fine.
    hope this helps,
    raj

  • Wrong email for new ID verification email, how can I log in to change the wrong email?

    Just changed my Apple ID but after I was done I realized the email I used as my ID is wrong.  Now when I try to sign into iTunes I am being asked to verify the new ID using the verification email sent to the new email, problem being that that new email is wrong and I can't access it.  How can I log back into my account to change that email?  Help please.

    Did you get an answer to this? i have a new email and I can't verify the old one as it is blocked so can't log into it.  Any help will be appreciated.... thanks

  • I just bought a iTunes card and its not accepting it.  It already sent it to the support team and they said they were going to get back to my within 24 hours and i am trying to buy a program in the app store for work.  How can I expedite this process?

    I just bought a iTunes card and its not accepting it.  It already sent it to the support team and they said they were going to get back to my within 24 hours and i am trying to buy a program in the app store for work.  How can I expedite this process?

    Has it been 24 hours?
    I take it this was a gift card.  iTunes Store:  Invalid, Inactive, or Illegible codes http://support.apple.com/kb/TS1292 - gift cards
    I don't know if this provides an alternative means: https://expresslane.apple.com ; select 'iTunes' in the first column; 'iTunes Store' in the second column
    If you are really desperate you could buy the app yourself, then request reimbursement.

  • I am trying to download xfinity tv go app. I can not find it in my App Store and can not download it from the comcast website. All I get is a blank screen in the App Store. My Apple ID is associated with a Canadian address. How can I find the app?

    I am trying to download xfinity tv go app. I can not find it in my App Store and can not download it from the comcast website. All I get is a blank screen in the App Store. My Apple ID is associated with a Canadian address. How can I find the app?

    Its possible the App is not available in the Canadian store if the link doesn't work for you.
    https://itunes.apple.com/us/app/xfinity-connect/id320788270?mt=8

  • How can I change the name of devices associated with my Apple ID in iTunes?

    We have 3 iPads and 4 iPhones in our family.  All of the iPads show up on the list of devices associated with my Apple ID as simply "iPad".  All of the iPhones show up simply as "iPhone", even though each device has a distinct name on the device itself (ie. Mark's iPhone).  How can I get the distinct name to show up on the list of devices so I can keep the list updated as we add or remove devices from our collection?

    Not it it's an @icloud.com, @me.com or @mac.com address.  In that case your choices are to either create an email alias within the existing account, which delivers email to your existing iCloud inbox (see http://help.apple.com/icloud/#/mm6b1a490a), or create a new iCoud account.  Note: alias addresses are permanently tied to the account that you create them in; they cannot be used to create a new iCloud account or be moved to a different account in the future.

Maybe you are looking for

  • I need help to recover my Entourage and iCal

    I have just synced my iphone - daily event - but this time all the calender entries hit the fan!  Oh dear, what a mess.  I appeared to have duplicateds of almost everything!  So I went through day by day deleting and updated profiles etc.  then I tho

  • How to do the Manual Depreciation for Closed Fisical Year (2009) in Feb2010

    Hi Experts, One Asset Start Using from 30.06.09. Capitalized Date is 30.06.09. But Asset (invoice) is Created, First Acquisition Date is 31.01.10. Manually Entered the Depreciation Date is 30.06.09. now i have to run the depreciation previous year (7

  • Error in the procedure while tried to increment the seq

    Hello , I tried the following but giving the errors.. Plz help me in this.. CREATE OR REPLACE PROCEDURE Seq_inc AS    vmaxarrec number(10);    vseq number(10);       select max(recid) into vmaxarrec from acc_rec;       select SEQ_ACC_REC.currval into

  • Need help with photo placement & sizing in iPhoto Calendar

    Hi, I am in the process of creating a photo calendar for my wife for Xmas in iPhoto. Initially I just dragged and dropped most of the photos into the layouts I selected without any cropping or anything figuring that they would print out on the calend

  • Outlook hotsync with Desktop

    I am having a problem getting my Palm TX to hotsync with my P.C.  The process goes well until it gets to the calendar. At that pint it stops. JAG Post relates to: Palm TX