PDA

View Full Version : Update - Kerio Firewall & Party Skins - the results are not good


Luv2DriveTT
08-05-2005, 11:14 PM
Hello all:

Recently my account was banned on a Party Skin with no warnings. Well, let me correct that.. no warnings that I ever received except one single pop-up that occurred while I forgot to turn on my Kerio Firewall.

Kerio would warm me daily of odd ports trying to open from within the Party skin client, yet I was able to play poker without any hindrance even when I blocked these ports.

Once I became banned, I un-installed the Poker Edge app, and cleaned my registry of any references to Poker Edge. I opened up a different Party skin expecting to see the standard port warnings I normally get from Kerio but they suddenly stopped!!!! Suddenly a light went off in my head..... all along I assumed the random port openings were ports trying to communicate to Party data about banned applications on my hard drive, when in reality I think it was the client trying to open up pop up warnings that I was using a banned application.

In other words.... Kerio may have actually hurt me by not providing a warning that Party knew I had Poker Edge installed.

Please note that my logic may be flawed, there is no guarantee that I am right (or wrong for that matter). But this does tell us quite a bit about what the Party client may or may not be doing:

1) I doubt very highly it is taking screen shots.
2) Party can determine if Poker Edge is installed, even if it is not being run. Party most likely does this via WMI programing interface, through a hard drive search, or through the registry.
3) There is no guarantee that running PE on a secondary computer will protect the user if it is run on the same network. Likewise the web interface may also fail the user over time. But for now they are both wonderful options I recommend exploring.

Good luck...

TT /images/graemlins/club.gif

bobdibble
08-05-2005, 11:46 PM
There would be no reason for party to open a port to display a popup message.

Luv2DriveTT
08-06-2005, 12:03 AM
[ QUOTE ]
There would be no reason for party to open a port to display a popup message.

[/ QUOTE ]

There would also be no reason for Party to open ports to scan a hard drive, to use the WMI interface, and there is also no reason for the Party client to not open ports when Poker Edge is not installed.

I know it doesn't seem logical from a programing point of view, but the facts remain. As a test I reinstalled Poker Edge and various ports (I say various because they seem to be random) try to open when the skin launches. When I remove Poker Edge, the random port opening stops.

Test it for yourself, you can verify my findings.

TT /images/graemlins/club.gif

Sniper
08-06-2005, 08:10 AM
Are you sure those ports aren't being opened by poker edge?

trying2learn
08-06-2005, 02:56 PM
just my two cents...i've been playing on party for three weeks now with poker-edge still on my computer, but not running. i haven't done anything with it since i got my warning email...

no kerio, or downloading of the new version...i just quit running it. i have had nothing happen as of yet, and i will be quite displeased if something does happen since i'm not using the program anymore.

shadow29
08-06-2005, 03:25 PM
I've used PE every night (more or less) for the last month on Euro. I'm still 1a ok there, no e-message, no popup, no e-mail. nothing.

I use Kerio, but nothing out of the ordinary has popped up.

dark_horse
08-06-2005, 04:35 PM
i tested TT's theory with kerio and uninstalled PE and any remnants it left behind by removing all references to it with regedit. i then launched eurobet and kerio still warns about those same random ports between 1200 and 3500 that aren't 2147 or 80. it can't be PE causing these ports, and the warning isn't causing these ports to open. it's something else. it could still be the skin searching for illicit software, or it could be something completely unrelated. same results with PP. no PE, removed everything from regedit, and the port requests remain.

can someone test this with a clean machine that has NEVER had PE installed on it? install kerio and see what ports are requested. thanks.

TheMetetron
08-06-2005, 11:14 PM
Thanks for the heads up on this thread TT... I've switched to remote for now. I'd rather not lose the $3k I have to have on site to be good for $10/20. Does kind of suck though.

At least I had the extra computer laying around.

Luv2DriveTT
08-07-2005, 01:45 AM
[ QUOTE ]
Are you sure those ports aren't being opened by poker edge?

[/ QUOTE ]

Positive. I've been discussing this with the developer of Poker Edge for more than a month now.

TT /images/graemlins/club.gif

Luv2DriveTT
08-07-2005, 01:48 AM
[ QUOTE ]
i tested TT's theory with kerio and uninstalled PE and any remnants it left behind by removing all references to it with regedit. i then launched eurobet and kerio still warns about those same random ports between 1200 and 3500 that aren't 2147 or 80. it can't be PE causing these ports, and the warning isn't causing these ports to open. it's something else. it could still be the skin searching for illicit software, or it could be something completely unrelated. same results with PP. no PE, removed everything from regedit, and the port requests remain.

can someone test this with a clean machine that has NEVER had PE installed on it? install kerio and see what ports are requested. thanks.

[/ QUOTE ]

Thats interesting. My friend Dylan had the same thing happen to him that you experienced.

As I continue to experiment the random port openings no longer occur on Empire, Poker Now, and Multi.. however they still occur (but only one foreign port, I forgot the #) on Party. Very odd.....

TT /images/graemlins/club.gif

bobdibble
08-07-2005, 02:40 AM
I'm not positive, but I think these ports are being used during the update process for some reason. It is really weird because they are UDP ports to your local machine.

However, I launched a skin I haven't used for awhile and it needed to be updated. Unless I kept hitting accept for the UDP traffic on that port, the thermomoter bar for the app update wouldn't move.

Very strange...

Luv2DriveTT
08-07-2005, 12:11 PM
[ QUOTE ]
I'm not positive, but I think these ports are being used during the update process for some reason. It is really weird because they are UDP ports to your local machine.

However, I launched a skin I haven't used for awhile and it needed to be updated. Unless I kept hitting accept for the UDP traffic on that port, the thermomoter bar for the app update wouldn't move.

Very strange...

[/ QUOTE ]

Tuyrn off your firewall during the update process, then restart it right before the app launches next time. It saves you some headaches.

TT /images/graemlins/club.gif

jnalpak
08-07-2005, 06:01 PM
FWIW, PARTY only uses 2 ports & an IP to function

IP: 66.212.229.183
TCP: 2047 & 2147

How do i know?
I send an email to party support asking for which ports i need to open to keep party running behind a firewall.

I dont think the other ports mean a thing since i got a warning letter and i have all ports blocked, unless defined.

The best defense against ANY port scan is to LOCK all ports down and start openning ports one at a time as the application demands it.