At http://news.gnhlug.org/article.php?sid=257 is:
I''m assuming the cracker is coming in from the net. What about just running tcpdump against the port he''s coming in through (telnet?) and capture everything? ***************************************************************** To unsubscribe from this list, send mail to [EMAIL PROTECTED] with the text 'unsubscribe gnhlug' in the message body. *****************************************************************