Back to Forums








View Full Version : Protowall: The Next Generation Peer Guardian


Big Booger
February 5th, 2004, 08:21 AM
http://techfocus.org/comments.php?id=4339&catid=39

ProtoWall is an app that is like PeerGuardian, but it will block much more. Thus far it will block Tcp-Ip/Udp/ICMP/IGMP and raw ip packets from entering or leaving your machine.

The help file for this app is located at http://bluetack.co.uk/pwhelp

Protowall is a driver-based blocking program that will be turning into a full firewall soon, but we wanted to release it as a alternative, due to the high memory usage that PeerGuardian has been experiencing with the last few builds.

Get it at http://www.bluetack.co.uk/forums/index.php?showforum=18

SupaStar
February 5th, 2004, 10:47 AM
And the verdict BB??

Big Booger
February 5th, 2004, 12:10 PM
It uses far less resources. It seems to work but I have yet to see anyone test it.. :D Try it out. See what you think.

Some other things I noticed, it continuously updates the IP ranges that it searches. It is more difficult to install than Peer Guardian, but with the online guide you can get it sorted in less than 2 minutes or so. It involves installing a driver in your network card properties.

Hopefully the installer can be configured to automatically install that driver.. along with installing the program in the future.

It does have a database updater built in.. that I do appreciate.

If I think of anything else I will post it here.
:D

Stripe
February 5th, 2004, 12:51 PM
This looks interesting. I'm not sure of any other application that actually works with the network card driver. Most typically just scan the incominig IP address.

I'll give it a go tonight and see how it is :D

cash_site
February 5th, 2004, 12:58 PM
You should call um RIAA and ask them to try to investigate your PC with the protowall working ?!

LOL

phishhead
February 5th, 2004, 13:10 PM
You should call um RIAA and ask them to try to investigate your PC with the protowall working ?!

LOL

go ahead stripe be the beta tester for riaa.

lynchknot
February 5th, 2004, 17:24 PM
Hmmm, maybe over my head. It just goes on and on allowing packets and not blocking anything. I have emule running, deleted Sygate rules, and disabled Sygate driver level protection.

**edit - I spoke too soon - I have 3 blocks - Taiwan government - and they are "packet to" - UDP

http://www.quickbase.com/up/8q9jbnau/g/rbba/eg/va/proto.JPG

lynchknot
February 5th, 2004, 18:44 PM
BB, what do you know about the block list manager. It advises the use of it. How to get?

Big Booger
February 5th, 2004, 23:13 PM
Go to their website Lynch. They have loads of information on it. Baycom was blocked on my machine 30 times in the first hour I had it launched. Make sure you have updated the latest DB of blocked IPs.
:D

lynchknot
February 5th, 2004, 23:30 PM
Yes, I have hit the update button - then it recommends "block list manager" I will check site - thanks.

SupaStar
February 6th, 2004, 01:49 AM
Running on my PC as we speak. Uses far fewer resources than PeerGuardian, half the RAM (7MB) and only 1-2% of my CPU (PG used to use anywhere from 20-70%!!)

lynchknot
February 6th, 2004, 01:59 AM
I'm seeing only 3,760K and 0-3% of cpu but it's probably not blocking anything at the moment (don't know if that makes a difference)

SupaStar
February 6th, 2004, 02:13 AM
I was RDC from work at the time so there was a lot of data going in and out.

lynchknot
February 6th, 2004, 02:51 AM
How far up have you guys set your, "log-o-meter"?

biker666_05
February 6th, 2004, 03:38 AM
i need help with protowall every time i enable it it disconnects me and then i cant connect

SupaStar
February 6th, 2004, 05:36 AM
@lynch - My log-o-meter is on the default setting, 3-quarters of the way up. I'm only logging bad packets..most are coming from port 80 :confused:

@biker - It disconnects you from the internet? What the... :confused:

cash_site
February 9th, 2004, 03:47 AM
@Supa, are bad packets to or from your port 80? It may be the reason why you had trouble with your sig? Although, your sig seems quite stable atm.

@biker, are you on dial-up and that what disconnects?

lynchknot
February 9th, 2004, 04:54 AM
Kinda funny that I changed all my emule ports by adding a 0 to the port (and made adjustments in my router config) - such as 4673 is now 40673 but they are still trying to get through 4673 - I don't know, it probably makes no difference - they maybe will try to get through all standard emule ports. I, mainly, see standard emule ports being blocked

Stripe
February 9th, 2004, 12:35 PM
I was able to install it and it works fine. Got tired of the allowed packets flying by so I disabled it.

I like the app. It's already blocked a few pop-up's as well :D

So far, (besides the pop-ups) nothing's been blocked. I still have Sygate going with my advanced rules intact as well as Peer Guardian for comparisions.

biker666_05
February 9th, 2004, 17:11 PM
im using dsl from sbc

Stripe
February 10th, 2004, 12:23 PM
im using dsl from sbc

Do you see any blocks before protowall disconnects you? If so, can you post what it blocks? I read somewhere where protowall was blocking router access. Also, did you download any block lists and if so, which one are you using?

biker666_05
February 10th, 2004, 20:29 PM
no blocks and i didnt download a block list

SupaStar
February 10th, 2004, 20:43 PM
@Supa, are bad packets to or from your port 80? It may be the reason why you had trouble with your sig? Although, your sig seems quite stable atm.

2004/02/10 17:47:11 [->] REJECTED - Source is DELL DELL split 2.3 PGIPDB (XXX.XXX.XXX.XXX) [protocol: TCP / destport: 80]

cash_site
February 12th, 2004, 03:45 AM
2004/02/10 17:47:11 [->] REJECTED - Source is DELL DELL split 2.3 PGIPDB (XXX.XXX.XXX.XXX) [protocol: TCP / destport: 80]
Hmmm... a little weird.

SupaStar
February 12th, 2004, 04:49 AM
Yep. Anyone else shed some light? Is it jsut someone from dell viewing the forum and trying to d/l my sig?

Big Booger
March 23rd, 2004, 15:17 PM
The protowall website is down.

lynchknot
March 23rd, 2004, 19:36 PM
something is wrong. I'm getting hit with packets from IANA reserved every few seconds or less - so far over 8000 this morning - it is slowing my connection down to a crawl. Any thoughts?

lynchknot
March 24th, 2004, 17:25 PM
protowall also using large memory - 99k

Big Booger
March 25th, 2004, 02:52 AM
99k a lot of memory? That is less than a megabyte???

When you are getting hit, the program is doing it's job. Do you have your performance optimized for programs or background applications? Try switching it and see if it improves.

:D

lynchknot
March 25th, 2004, 03:27 AM
99,000k - is more than any app i'm using. :) getting hit every second - now by mostly Red sherrif. - http://cexx.org/sheriff.htm

Big Booger
March 25th, 2004, 05:29 AM
You should have written 99,000KB.. not 99KB.. :D That's 99MB roughly which is quite a lot.

But with 1GB of ram, it shouldn't even effect your system in the slightest.. now CPU usage might be a different matter...

You might want to configure your router software to block the traffic, and use protowall as a backup?? You might want to reload protowall? Does this happen after a fresh reboot?

lynchknot
March 25th, 2004, 05:42 AM
I blocked the red sherrif range in my router - so far down to 6,440k - much better

*edit - opps still coming through on the IP I blocked not as much though- its destination is emule ports

Big Booger
March 25th, 2004, 05:48 AM
Change your default emule port in emule to 4661-9.. and open that port in your router.. the number of hits you get from these companies should be reduced.. I use 4663 on my setup.

lynchknot
March 25th, 2004, 05:56 AM
I have changed my ports a long time ago. I'm using 10000 and 40660. They still try to get 4662 as well as the new ports i'm using

I have blocked this yet it still comes through.


http://www.quickbase.com/up/8q9jbnau/g/rbgy/eg/va/mule2.PNG

http://www.quickbase.com/up/8q9jbnau/g/rbgz/eg/va/mule.PNG

Big Booger
March 25th, 2004, 14:03 PM
Dump your shared/incoming folder as soon as you get the files.. the less you share the less they scan.
:D

Your firewall on your router should kick it out.. strange indeed. What they need is a program that would bounce back any scan from a list of know baddies..

That way for every scan they do multiple packets would bounce back and effectively slow down or even bump offline the server that is doing the scanning.. you scan 1 million PCs, and 1 million PCs bounce back multiple packets, well you can see how easy that would f uck them up.
:D

lynchknot
March 25th, 2004, 15:51 PM
I'm not liking this D-link much anymore. I'm having problems with emule connecting. If I change ports D-link will not allow it or won't pay attentions to settings - even after re-boot.


I don't share much - yes, I do move files out as soon as I get them. I leave some apps in though.

lynchknot
March 25th, 2004, 18:22 PM
Got a ? about proto and BLM. Do I need to manually update protowall's IP range after downloading with BLM? There is no directory for automatic update retrieval in Protowall.

shadow_warez
March 25th, 2004, 20:19 PM
it dont wanna work for my comp lol,. keeps saying protowall.sys not loaded?i tryed installing, wait for it to finnish then try same thing,

shadow_warez
March 25th, 2004, 20:29 PM
heres the message i get after manuelly installin the xp driver,

lynchknot
March 26th, 2004, 00:00 AM
so do you see this?

http://www.quickbase.com/up/8q9jbnau/g/rbg8/eg/va/55.PNG