All of lore.kernel.org
 help / color / mirror / Atom feed
* Logging packet owner
@ 2003-12-10 10:47 John Guerrero
  0 siblings, 0 replies; 5+ messages in thread
From: John Guerrero @ 2003-12-10 10:47 UTC (permalink / raw)
  To: netfilter

Hi folks, I browsed the last 7 months of archives and 
didn't see this question addressed.

Are there plans to allow logging the packet owner?  For 
example, I get rogue DNS requests eminating from my 
workstation and I'd like to know which process is doing 
this.  

And for that matter, is there a place on the netfilter.org 
website that lists the completed and upcoming features?

Thanks,
jlg


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Logging packet owner
@ 2003-12-11 21:34 John E. Leon Guerrero
  2003-12-11 22:08 ` Eric Leblond
  0 siblings, 1 reply; 5+ messages in thread
From: John E. Leon Guerrero @ 2003-12-11 21:34 UTC (permalink / raw)
  To: netfilter

Hi folks, I browsed the last 7 months of archives and didn't see this 
question addressed.

Are there plans to allow logging the packet owner?  For example, I get 
rogue DNS requests eminating from my workstation and I'd like to know 
which process is doing this.
 
And for that matter, is there a place on the netfilter.org website that 
lists the completed and upcoming features?

Thanks,
jlg



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Logging packet owner
  2003-12-11 21:34 John E. Leon Guerrero
@ 2003-12-11 22:08 ` Eric Leblond
  2003-12-15 19:34   ` John E. Leon Guerrero
  0 siblings, 1 reply; 5+ messages in thread
From: Eric Leblond @ 2003-12-11 22:08 UTC (permalink / raw)
  To: John E. Leon Guerrero; +Cc: netfilter

[-- Attachment #1: Type: text/plain, Size: 725 bytes --]

Le jeu 11/12/2003 à 22:34, John E. Leon Guerrero a écrit :
> Hi folks, I browsed the last 7 months of archives and didn't see this 
> question addressed.
> 
> Are there plans to allow logging the packet owner?  For example, I get 
> rogue DNS requests eminating from my workstation and I'd like to know 
> which process is doing this.

you can do full user filtering and activity logging with the nufw
project which is based on netfilter :
	http://www.nufw.org/
Complete logging of dropped packets will be available on the next
release (0.6.1), which is planned to be available on monday (code is in
cleaning and testing phase).

BR,
-- 
Eric Leblond
Nufw, Now User Filtering Works (http://www.nufw.org)

[-- Attachment #2: Ceci est une partie de message numériquement signée. --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Logging packet owner
@ 2003-12-12  5:13 Babar Kazmi
  0 siblings, 0 replies; 5+ messages in thread
From: Babar Kazmi @ 2003-12-12  5:13 UTC (permalink / raw)
  To: eric, jguerrero; +Cc: netfilter

[-- Attachment #1: Type: text/html, Size: 1892 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Logging packet owner
  2003-12-11 22:08 ` Eric Leblond
@ 2003-12-15 19:34   ` John E. Leon Guerrero
  0 siblings, 0 replies; 5+ messages in thread
From: John E. Leon Guerrero @ 2003-12-15 19:34 UTC (permalink / raw)
  To: Eric Leblond; +Cc: netfilter

hi eric, thanks for pointing out that project.  it's a little much for 
my immediate needs, but i do see it's usefulness in a larger context :)

for those would be interested in what i did in the meantime, here's my 
workaround for finding the process that was issuing rogue dns queries:
1. log and allow outgoing DNS packet
2. deny incoming DNS packets
  -hopefully the process waits around long enough for a response
3. issue lsof -n -i UDP:53 as soon as the outgoing log message hits
  -the -n is important or it can hang waiting for DNS as well :)
4. ps fax is a good idea if it's not obvious what the parent process is

good luck out there,
jlg

Eric Leblond wrote:

>Le jeu 11/12/2003 à 22:34, John E. Leon Guerrero a écrit :
>  
>
>>Hi folks, I browsed the last 7 months of archives and didn't see this 
>>question addressed.
>>
>>Are there plans to allow logging the packet owner?  For example, I get 
>>rogue DNS requests eminating from my workstation and I'd like to know 
>>which process is doing this.
>>    
>>
>
>you can do full user filtering and activity logging with the nufw
>project which is based on netfilter :
>	http://www.nufw.org/
>Complete logging of dropped packets will be available on the next
>release (0.6.1), which is planned to be available on monday (code is in
>cleaning and testing phase).
>
>BR,
>  
>



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-12-15 19:34 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-10 10:47 Logging packet owner John Guerrero
  -- strict thread matches above, loose matches on Subject: below --
2003-12-11 21:34 John E. Leon Guerrero
2003-12-11 22:08 ` Eric Leblond
2003-12-15 19:34   ` John E. Leon Guerrero
2003-12-12  5:13 Babar Kazmi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.