Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: WINDUMP SYNTAX ASSISTANCE.....

From: Bill Martin <martin.b(at)attbi.com>
Date: Wed Jan 29 2003 - 02:09:52 EST


If you read the MAN (or help for you windows people) pages, this is not difficult. Mots of it is based on TCPDump type usages:

windump ((port 80) and (net !192.168.1.0/24))

Change the port,and the net address as needed
-bill-

-----Original Message-----

From: Jason Beauford [mailto:Jbeauford@mill-max.com] Sent: Tuesday, January 28, 2003 10:27 AM To: focus-ids@securityfocus.com
Subject: WINDUMP SYNTAX ASSISTANCE.....

Forum,

I am looking for the Windump syntax to record only the packets that involve a particular host and those hosts outside of our internal network. I've tried the "host hostname and not src net localnet, but I am still missing half of the traffic as it only gives me ingress traffic. I still need to record egress traffic. So I try host hostname and not dst net localnet. This gives me only egress and not ingress. If I try without same syntax without the src or dst, I get no traffic. Can anyone point me in the right direction with this?

Thanks in advance.

Regards,

Do you need help?X

Jason M. Beauford. Received on Wed Jan 29 12:24:50 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:07 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library