How do I snoop unauthorised traffic
- From: Peter Lowrie <peterlowrie@xxxxxxxxxxxxxxx>
- Date: Tue, 12 Sep 2006 00:46:53 +1200
One of the Windows 2000 boxs is sending data out of the network to some host
on the internet. My gateway is Mandrake Linux 8.2 running straight
iptables. I've tried tcpdump against the internet facing NIC but the data
are inconclusive.
How do I determine what traffic is leaving the network and determine what
host it is being sent to, then what string do I use in
the /etc/sysconfig/iptables file to block it?
Thanks
Peter
.
- Follow-Ups:
- Re: How do I snoop unauthorised traffic
- From: Llanzlan Klazmon
- Re: How do I snoop unauthorised traffic
- From: Tauno Voipio
- Re: How do I snoop unauthorised traffic
- From: Moe Trin
- Re: How do I snoop unauthorised traffic
- Prev by Date: Re: Name Based Routing
- Next by Date: How to get first free udp port ?
- Previous by thread: port 110 very slow
- Next by thread: Re: How do I snoop unauthorised traffic
- Index(es):
Relevant Pages
|