[tcpdump-workers] how to detect a bridged pseudo mac-addr.

2005-03-23 Thread Per Engelbrecht
Hi all I have a big problem finding a customer with tcpdump (dedicated serverhosting / ~300 servers / switched network [mac-lockdown] / no "central" firewall other than my BGP-router protecting itself) who's spamming the world using a fake IP and a pseudo VMware mac-addr. in the mail-header. Th

[tcpdump-workers]

2005-03-23 Thread FatRiSha
hello all, I would like to know the correlation between 'libpcap', 'linux' & bpf. I found someone said that there's no BPF in Linux, instead there's a bpf emulator that works on 'user space' not 'kernel space', so there must be many packets dropped or cannot be processed? is that right? Thanks a

Re: [tcpdump-workers] tcpdump on Nokia IP380 to grab http headers

2005-03-23 Thread Guy Harris
Walzer, Jeff wrote: I want to run tcpdump on the Nokia box to make sure that is the only header and that I'm not missing any that might get stripped. Does tcpdump allow me to grab http headers and if so what command options do I need to use to grab that info? Tcpdump grabs raw packet data - it does

[tcpdump-workers] tcpdump on Nokia IP380 to grab http headers

2005-03-23 Thread Walzer, Jeff
We are trying to block the ability to do file transfers through Msn Messenger on our Checkpoint NG w/AI R55 firewall. I've seen various articles stating that Msn Messenger file transfer uses ports 6891-6900, but when I do a packet capture I see nothing but traffic over 1863, or port 80 for those wh

[tcpdump-workers] Automatic report from sources (tcpdump libpcap htdocs) between 22.03.2005 - 23.03.2005 GMT

2005-03-23 Thread Automatic cvs log generator /tcpdump/bin/makelog
CVS log entries from 22.03.2005 (Tue) 10:07:08 - 23.03.2005 (Wed) 10:07:03 GMT = Summary by authors = Author: hannes File: tcpdump/print-bgp.c; Revisions: 1.90, 1.89