Re: Possible security problem?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Possible security problem?

From: Simon Slavin <slavins.delete.these.four.words@hearsay.demon.co.uk>
Date: Sun Jul 31 2005 - 00:38:38 CEST

On 28/07/2005, Alex wrote in message <dcacqn$kh2$2@oheron.kent.ac.uk>:
 
> NormanM wrote:
> > My money is on, "Yes". UDP to port 1026; and my router logs are filled
> > with incoming UDP packets to port 1026. I have always suspected Windows
> > Messenger Service spam. Can you find a way to examine those packets?
> > Are there Mac packet sniffers?
>
> Ethereal - http://www.ethereal.com
>
> Works under most UNIXes (including OS X) and Windows.

You don't even need that. 'tcpdump' will do it. It's complicated to
use but can do everything, including monitoring only packets from/to
specific ports. Use 'man tcpdump' for more info.

Simon.

-- 
Using pre-release version of newsreader.
Please tell me if it does weird things.
Received on Thu Sep 29 19:59:53 2005