log data passed in outgoing connections

  • macrokill
  • Born
  • Born
  • No Avatar
  • Joined: Jul 30, 2004
  • Posts: 2
  • Status: Offline

Post July 30th, 2004, 12:27 pm

Hi!
I run a dedicated FreeBSD server with root access.
Some programs working on this server
establish outgoing connections to other web servers.
I need to see what data exactly they send out and probably log this info.
Preferrably some free software that would transparently log this stuff
without making problems to the server or breaking connections.
Or maybe I can just configure some firewall or smth...
Any advice welcome!
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post July 30th, 2004, 12:27 pm

  • Daemonguy
  • Moderator
  • Web Master
  • User avatar
  • Joined: Jan 23, 2004
  • Posts: 2673
  • Loc: Somewhere outside the box in Sarasota, FL.
  • Status: Offline

Post July 30th, 2004, 12:49 pm

Load snort, configure your own ruleset -- easy to write -- to capture and log said data.

http://www.snort.org

Cheers.
(Yes, it is technically an IDS, but can be used for exactly the purpose you intend. )
"It's always a long day, 86,400 won't fit into a short."
  • macrokill
  • Born
  • Born
  • No Avatar
  • Joined: Jul 30, 2004
  • Posts: 2
  • Status: Offline

Post August 21st, 2004, 12:41 pm

ye maybe snort would be ok, but I just came across a simple tool - tcpflow, that does exactly what I need and the syntax is same as for tcpdump. Those who have same problem will love it! :)

Post Information

  • Total Posts in this topic: 3 posts
  • Users browsing this forum: No registered users and 48 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.