From owner-freebsd-questions@FreeBSD.ORG Thu Aug 18 17:02:00 2011 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 08C961065673 for ; Thu, 18 Aug 2011 17:02:00 +0000 (UTC) (envelope-from alexus@gmail.com) Received: from mail-yw0-f54.google.com (mail-yw0-f54.google.com [209.85.213.54]) by mx1.freebsd.org (Postfix) with ESMTP id BB1B58FC13 for ; Thu, 18 Aug 2011 17:01:59 +0000 (UTC) Received: by ywo32 with SMTP id 32so1896104ywo.13 for ; Thu, 18 Aug 2011 10:01:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=wR/lrKlDecKWbSLvlfby5SMlSU9SAndyCzyOai6DoCo=; b=wc3sCHETvaNY3UK/y0wkGEp4TUU9/+bshP5dGttb7t7JgOiSF+5CUgX7q6Ndg9rRFg jIeMlhGs3Z+3owCuNAUk2Nx9BvGKQlgtplCATVTMWnw+Y+YNG7bqiGqn8qg5ZbHhDpfc s/xU97+m5ldhWthwTgR3G+3wq9sTuYwqGsHZo= MIME-Version: 1.0 Received: by 10.143.97.16 with SMTP id z16mr499643wfl.357.1313686918670; Thu, 18 Aug 2011 10:01:58 -0700 (PDT) Received: by 10.68.60.164 with HTTP; Thu, 18 Aug 2011 10:01:58 -0700 (PDT) In-Reply-To: References: <033753EAA5A5EE53C17333A5@utd71538.utdallas.edu> Date: Thu, 18 Aug 2011 13:01:58 -0400 Message-ID: From: alexus To: Chuck Swiger Content-Type: text/plain; charset=UTF-8 Cc: freebsd-questions@freebsd.org Subject: Re: looking for a spammer/virii/malware .... on my system X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 Aug 2011 17:02:00 -0000 right, but what seems to be (according to headers) someone makes a connection from my box to theirs over the web (80/443) so i'm going see if I can see anything, if not then i'll keep it blocked until I figure out something else to find who does that... On Thu, Aug 18, 2011 at 12:42 PM, Chuck Swiger wrote: > On Aug 18, 2011, at 9:36 AM, alexus wrote: >> su-3.2# tcpdump -nnAvvvw webmail.west.cox.net 'dst host 68.6.19.1 and >> (dst port 80 or 443)' >> tcpdump: listening on bce0, link-type EN10MB (Ethernet), capture size 96 bytes >> Got 0 >> >> let's see what I capture... > > You're going to capture traffic of people reading webmail from Cox.net. > > However, as much as that might be interesting, it is not useful > for detecting outbound spam from a machine or network.... > > Regards, > -- > -Chuck > > -- http://alexus.org/