mass packet sniffer?

Networking and broadband talkabout. Need help with that new router or setting up a network?
Post Reply
User avatar
ShibasScotch
Senior Member
Posts: 413
Joined: Mon Mar 11, 2002 12:44 am
Contact:

mass packet sniffer?

Post by ShibasScotch »

I have this bad feeling that one of my 300 comptuers on the domain is spamming. I monitor all the traffic on my mailserver, so I know that it is not comming from there, however, it is comming from the global IP address in my firewall? is there anyway that I can monitor all the outgoing traffic? I have websense setup for filtering, but that is only http and ftp requests mostly... there must be something else that is doing this spamming..
thanks!
Stupid people do stupid things, smart people outsmart each other, then themselves.
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

you need a packet sniffing prog. also you need to set the port on the switch to foward all request to it not just the ones bound to that IP. I used to have one but for the life of me i cant find it or remember what it was called... but just look for packet sniffer.
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

Ethereal will work most likely.

Can't remember the site offhand, Google it.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

Originally posted by Busby
Ethereal will work most likely.

Can't remember the site offhand, Google it.


Thats the one i had. it works good.
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
User avatar
ShibasScotch
Senior Member
Posts: 413
Joined: Mon Mar 11, 2002 12:44 am
Contact:

Post by ShibasScotch »

great thanks !
I had heard of it, I just didnt know if it would work for the whole domain, I will try it out.
Stupid people do stupid things, smart people outsmart each other, then themselves.
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

well... if your wohle domain is on switches its only gonna se whats comming in and going out of the computer its on... you need to set a port on a switch to send all traffic (brodcast) like a hub would to see all of the traffic.
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
User avatar
ShibasScotch
Senior Member
Posts: 413
Joined: Mon Mar 11, 2002 12:44 am
Contact:

Post by ShibasScotch »

maybe i can try it out on the firewall or router..
Stupid people do stupid things, smart people outsmart each other, then themselves.
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

well cahnces are if whatever is spamming its gonna try and spam everything on the netowrk so you should see packets comming from that machine (the one causing problems) from anywhere on the network.
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
Post Reply