Date: Thu, 18 Aug 2011 09:42:14 -0700 From: Chuck Swiger <cswiger@mac.com> To: alexus <alexus@gmail.com> Cc: freebsd-questions@freebsd.org Subject: Re: looking for a spammer/virii/malware .... on my system Message-ID: <F318D000-CCFF-4AFA-8CCD-B3AD70392BED@mac.com> In-Reply-To: <CAJxePN%2BHU3_8_ELie0NPXMNd9OS1=_MuHJnhPNFRScOTb=A%2Byw@mail.gmail.com> References: <CAJxePNKiEmdimqgdtS-jYPOxExL6a489SR5JW2kCd25X6QFuHQ@mail.gmail.com> <D49826AA-9FF9-4848-A92A-5FF29A78679B@mac.com> <CAJxePNJ6k=0Na0Zcz7_j4EAs3QNHOSnSENp3AWVdfiirV_h_pA@mail.gmail.com> <033753EAA5A5EE53C17333A5@utd71538.utdallas.edu> <CAJxePN%2BHU3_8_ELie0NPXMNd9OS1=_MuHJnhPNFRScOTb=A%2Byw@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
On Aug 18, 2011, at 9:36 AM, alexus wrote: > su-3.2# tcpdump -nnAvvvw webmail.west.cox.net 'dst host 68.6.19.1 and > (dst port 80 or 443)' > tcpdump: listening on bce0, link-type EN10MB (Ethernet), capture size 96 bytes > Got 0 > > let's see what I capture... You're going to capture traffic of people reading webmail from Cox.net. However, as much as that might be interesting, it is not useful for detecting outbound spam from a machine or network.... Regards, -- -Chuck
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F318D000-CCFF-4AFA-8CCD-B3AD70392BED>