Re: Strange Packet logs in ipchains

From: Bear Giles (bgiles@coyotesong.com)
Date: 03/26/03

  • Next message: Burton M. Strauss III: "RE: Strange Packet logs in ipchains"
    Date: Wed, 26 Mar 2003 13:30:16 -0700
    From: Bear Giles <bgiles@coyotesong.com>
    To: Sam Dirk <samdirk@online.ie>
    
    

    Sam Dirk wrote:
    > The packets
    > were seen three times over the course of the day but lasted
    > for only one - two seconds so it was impossible to get a
    > tcpdump.

    Use snort, or something similiar to it, and set it up on a box
    without ipchains filtering. Set up rules that are essentially the
    complement of your firewall rules, and you'll catch all traffic
    that the firewalls are rejecting. There's then no need to run
    tcpdump explicity (or hit yourself in the head when you realize
    that tcpdump is running behind the packet filtering so it would
    never record anything).

    You can even take this to an extreme - set it up on your
    firewall(s) and log ALL traffic trying to enter or leave your
    network. Let another process prune out the expected traffic, then
    examine what's left....

    Bear

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.surfcontrol.com/go/zsfsbl1


  • Next message: Burton M. Strauss III: "RE: Strange Packet logs in ipchains"

    Relevant Pages

    • Re: Packet capturing, iptables and eth0 vs. dummy0
      ... The problem was with tcpdump since I knew that packets were being ... >> I've noticed that, no matter what filtering is iptables doing, ... therefore you capture packets way before they enter the IPv4 ...
      (Linux-Kernel)
    • Re: pf & tcpdump
      ... > Is there a way to have tcpdump only showing packed that have pass the ... > not letting unwanted packets in. ... tcpdump sees packets before they're passed to the firewall coming in, ... Easiest way to see firewall rules are working is to add logging to them. ...
      (freebsd-net)
    • Re: pf & tcpdump
      ... not letting unwanted packets in. ... tcpdump sees packets before they're passed to the firewall coming in, ... Easiest way to see firewall rules are working is to add logging to them. ...
      (freebsd-net)
    • Re: ntpd fails to synchronize on FreeBSD 6.3-STABLE
      ... 12 packets received by filter ... Then let the tcpdump go for about 15 minutes. ... Firewall on my router/gateway is disabled, ... # shutdown -r now ...
      (freebsd-stable)
    • Re: flooding an embedded device with isic and tcpreplay causing different results
      ... You can try use -nn option at tcpdump too, ... now I wondering why the tcpreplay attack don't f*** up the SOHO. ... The tcpdump isn't complete because of "dropped by kernel" packets - ... listening on eth0, link-type EN10MB, capture size ...
      (Pen-Test)

  • Quantcast