DSNIFF: tcpdump expression in mailsnarf?
Steve Moon <[email protected]> 04 Apr 2003 15:20:18 -0500
| Newsgroups | gmane.network.dsniff |
|---|---|
| Message-ID | <[email protected]> |
What is the secret formula to get a tcpdump expression to work with mailsnarf? I'm using OpenBSD 3.1, and have tried both a package install as well as compiling dsniff manually. I'm trying to catch only outgoing messages for a HIPAA audit. When I do a: /usr/local/sbin/mailsnarf -i xl0 . I will get all mail (incoming and outgoing). When I do a: /usr/local/sbin/mailsnarf -i xl0 . host xx.yy.zz.aa I seem to just get traffic for that host. When I do a: /usr/local/sbin/mailsnarf -i xl0 . src host xx.yy.zz.aa I get no output at all. Ideally I could use a 'src net aa.bb.cc.dd/24 port 25' filter so I just get smtp originating from my network. I've tried using various quoting techniques for the tcpdump expression (single quotes, double quotes, no quotes) Any help appreciated. Thanks! Steve- -- Steve Moon <[email protected]> ------------------------------------------------------------------------ The information contained in this communication is intended only for the use of the recipient(s) named above. It may contain information that is privileged or confidential, and may be protected by State and/or Federal Regulations. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication, or any of its contents, is strictly prohibited. If you have received this communication in error, please return it to the sender immediately and delete the original message and any copy of it from your computer system. If you have any questions concerning this message, please contact the sender, or our Privacy Office at [email protected] ------------------------------------------------------------------------