Re: How do I snoop unauthorised traffic
- From: Tauno Voipio <tauno.voipio@xxxxxxxxxxxxx>
- Date: Tue, 12 Sep 2006 13:55:09 GMT
Peter Lowrie wrote:
One of the Windows 2000 boxs is sending data out of the network to some host
on the internet. My gateway is Mandrake Linux 8.2 running straight
iptables. I've tried tcpdump against the internet facing NIC but the data
are inconclusive.
How do I determine what traffic is leaving the network and determine what
host it is being sent to, then what string do I use in
the /etc/sysconfig/iptables file to block it?
Windows is pretty talkative out-of-the-box. You probably want
to disable the ports 135 to 193 and 445 for both TCP and UDP.
--
Tauno Voipio
tauno voipio (at) iki fi
.
- References:
- How do I snoop unauthorised traffic
- From: Peter Lowrie
- How do I snoop unauthorised traffic
- Prev by Date: Re: port 110 very slow
- Next by Date: Re: How to get first free udp port ?
- Previous by thread: Re: How do I snoop unauthorised traffic
- Next by thread: Re: How do I snoop unauthorised traffic
- Index(es):
Relevant Pages
|