[fw-wiz] IPTables logging target: show pid/program name?

From: Chris de Vidal (chris_at_devidal.tv)
Date: 11/14/03

  • Next message: William Stearns: "Re: [fw-wiz] IPTables logging target: show pid/program name?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 14 Nov 2003 11:46:28 -0500 (EST)
    
    

    I have several rules like this:
    /sbin/iptables --append OUTPUT --jump LOG --log-level DEBUG --log-prefix
    "OUTPUT packet died: "
    at the bottom of my OUTPUT chain to debug which outgoing packets get
    dropped so I can adjust the rules as necessary. It's been working well
    for months.

    Trouble is I don't always know which program is producing these packets.

    It would be handy to also see the pid and/or program name responsible for
    these packets. Any idea how?

    /dev/idal
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: William Stearns: "Re: [fw-wiz] IPTables logging target: show pid/program name?"

    Relevant Pages

    • RE: Cisco IOS exploit (44020)
      ... various protocols and sends 19 packets ... Cisco IOS device and is the TTL subtracted by 255. ... DEBUG: Protocol: 53 ...
      (Bugtraq)
    • RE: Cisco IOS exploit (44020)
      ... Subject: Cisco IOS exploit ... various protocols and sends 19 packets ... DEBUG: Protocol: 53 ...
      (Bugtraq)
    • [Full-Disclosure] [Fwd: RE: Cisco IOS exploit (44020)]
      ... Subject: Cisco IOS exploit ... various protocols and sends 19 packets ... DEBUG: Protocol: 53 ...
      (Full-Disclosure)
    • Re: Platform Builder Ignoring BOOTME message
      ... beitman AT applieddata DOT net ... My debug port just asserts that the uboot is shooting out the packets ... those packets, and waiting for the runtime image to be uploaded into it. ...
      (microsoft.public.windowsce.platbuilder)
    • Re: Platform Builder Ignoring BOOTME message
      ... Also see the debug message on your device (which are sent out of the ... firewall blocks BOOTME packets from PB and/or reply to them. ... The Kernel Debugger has been disconnected successfully. ...
      (microsoft.public.windowsce.platbuilder)