* Logging packet owner
@ 2003-12-10 10:47 John Guerrero
0 siblings, 0 replies; 5+ messages in thread
From: John Guerrero @ 2003-12-10 10:47 UTC (permalink / raw)
To: netfilter
Hi folks, I browsed the last 7 months of archives and
didn't see this question addressed.
Are there plans to allow logging the packet owner? For
example, I get rogue DNS requests eminating from my
workstation and I'd like to know which process is doing
this.
And for that matter, is there a place on the netfilter.org
website that lists the completed and upcoming features?
Thanks,
jlg
^ permalink raw reply [flat|nested] 5+ messages in thread
* Logging packet owner
@ 2003-12-11 21:34 John E. Leon Guerrero
2003-12-11 22:08 ` Eric Leblond
0 siblings, 1 reply; 5+ messages in thread
From: John E. Leon Guerrero @ 2003-12-11 21:34 UTC (permalink / raw)
To: netfilter
Hi folks, I browsed the last 7 months of archives and didn't see this
question addressed.
Are there plans to allow logging the packet owner? For example, I get
rogue DNS requests eminating from my workstation and I'd like to know
which process is doing this.
And for that matter, is there a place on the netfilter.org website that
lists the completed and upcoming features?
Thanks,
jlg
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Logging packet owner
2003-12-11 21:34 John E. Leon Guerrero
@ 2003-12-11 22:08 ` Eric Leblond
2003-12-15 19:34 ` John E. Leon Guerrero
0 siblings, 1 reply; 5+ messages in thread
From: Eric Leblond @ 2003-12-11 22:08 UTC (permalink / raw)
To: John E. Leon Guerrero; +Cc: netfilter
[-- Attachment #1: Type: text/plain, Size: 725 bytes --]
Le jeu 11/12/2003 à 22:34, John E. Leon Guerrero a écrit :
> Hi folks, I browsed the last 7 months of archives and didn't see this
> question addressed.
>
> Are there plans to allow logging the packet owner? For example, I get
> rogue DNS requests eminating from my workstation and I'd like to know
> which process is doing this.
you can do full user filtering and activity logging with the nufw
project which is based on netfilter :
http://www.nufw.org/
Complete logging of dropped packets will be available on the next
release (0.6.1), which is planned to be available on monday (code is in
cleaning and testing phase).
BR,
--
Eric Leblond
Nufw, Now User Filtering Works (http://www.nufw.org)
[-- Attachment #2: Ceci est une partie de message numériquement signée. --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Logging packet owner
@ 2003-12-12 5:13 Babar Kazmi
0 siblings, 0 replies; 5+ messages in thread
From: Babar Kazmi @ 2003-12-12 5:13 UTC (permalink / raw)
To: eric, jguerrero; +Cc: netfilter
[-- Attachment #1: Type: text/html, Size: 1892 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Logging packet owner
2003-12-11 22:08 ` Eric Leblond
@ 2003-12-15 19:34 ` John E. Leon Guerrero
0 siblings, 0 replies; 5+ messages in thread
From: John E. Leon Guerrero @ 2003-12-15 19:34 UTC (permalink / raw)
To: Eric Leblond; +Cc: netfilter
hi eric, thanks for pointing out that project. it's a little much for
my immediate needs, but i do see it's usefulness in a larger context :)
for those would be interested in what i did in the meantime, here's my
workaround for finding the process that was issuing rogue dns queries:
1. log and allow outgoing DNS packet
2. deny incoming DNS packets
-hopefully the process waits around long enough for a response
3. issue lsof -n -i UDP:53 as soon as the outgoing log message hits
-the -n is important or it can hang waiting for DNS as well :)
4. ps fax is a good idea if it's not obvious what the parent process is
good luck out there,
jlg
Eric Leblond wrote:
>Le jeu 11/12/2003 à 22:34, John E. Leon Guerrero a écrit :
>
>
>>Hi folks, I browsed the last 7 months of archives and didn't see this
>>question addressed.
>>
>>Are there plans to allow logging the packet owner? For example, I get
>>rogue DNS requests eminating from my workstation and I'd like to know
>>which process is doing this.
>>
>>
>
>you can do full user filtering and activity logging with the nufw
>project which is based on netfilter :
> http://www.nufw.org/
>Complete logging of dropped packets will be available on the next
>release (0.6.1), which is planned to be available on monday (code is in
>cleaning and testing phase).
>
>BR,
>
>
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2003-12-15 19:34 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-10 10:47 Logging packet owner John Guerrero
-- strict thread matches above, loose matches on Subject: below --
2003-12-11 21:34 John E. Leon Guerrero
2003-12-11 22:08 ` Eric Leblond
2003-12-15 19:34 ` John E. Leon Guerrero
2003-12-12 5:13 Babar Kazmi
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.