DSNIFF: tcpdump expression in mailsnarf?

Steve Moon <[email protected]> 04 Apr 2003 15:20:18 -0500
Newsgroups gmane.network.dsniff
Message-ID <[email protected]>
What is the secret formula to get a tcpdump expression to work with
mailsnarf?

I'm using OpenBSD 3.1, and have tried both a package install as well as
compiling dsniff manually.

I'm trying to catch only outgoing messages for a HIPAA audit.

When I do a: /usr/local/sbin/mailsnarf -i xl0 .
I will get all mail (incoming and outgoing).

When I do a: /usr/local/sbin/mailsnarf -i xl0 . host xx.yy.zz.aa
I seem to just get traffic for that host.

When I do a: /usr/local/sbin/mailsnarf -i xl0 . src host xx.yy.zz.aa
I get no output at all.

Ideally I could use a 'src net aa.bb.cc.dd/24 port 25' filter so I just
get smtp originating from my network.

I've tried using various quoting techniques for the tcpdump expression
(single quotes, double quotes, no quotes)

Any help appreciated. Thanks!
Steve-

-- 
Steve Moon <[email protected]>



------------------------------------------------------------------------
The information contained in this communication is intended
only for the use of the recipient(s) named above. It may
contain information that is privileged or confidential, and
may be protected by State and/or Federal Regulations. If
the reader of this message is not the intended recipient,
you are hereby notified that any dissemination,
distribution, or copying of this communication, or any of
its contents, is strictly prohibited. If you have received
this communication in error, please return it to the sender
immediately and delete the original message and any copy
of it from your computer system. If you have any questions
concerning this message, please contact the sender, or
our Privacy Office at [email protected]
------------------------------------------------------------------------