LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-10-2008, 07:49 AM   #1
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
Program to monitor e-mail sent from my LAN?


Hello,

My ISP has told me that it detected spam coming from my connection. I find this rather unlikely*, but I'd like to check. My router is a Debian box; what is/are some program(s) that will let me monitor mail sent from all boxes on the LAN to all destinations?


* the router is a Linux box, and the clients are a Vista w/ AV and firewall, an XP VM not used for internet, and two Macs.
 
Old 07-10-2008, 07:56 AM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
tcpdump can do that.
 
Old 07-10-2008, 02:48 PM   #3
simonapnic
Member
 
Registered: Jul 2008
Posts: 70

Rep: Reputation: 16
Post

You might want to run a packet sniffer, which can sniff SMTP traffic and identify the objects (recipient, message..). I suggest Wireshark.
Check the mail queue as well, it might have some unsent data if the mails were sent from your connection.
What SMTP daemon are you using ? Exim ? Sendmail ?
 
Old 07-10-2008, 05:35 PM   #4
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Original Poster
Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
postfix, but LAN clients don't send mail through the router. The only mail that's been sent from the Linux router in the past two weeks are the daily logwatches.

I don't have a GUI on this machine, and it's remote at the moment. I will try tcpdump and see if wireshark has a non-GUI mode.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LAN traffic monitor vedang Linux - Server 1 02-11-2008 04:38 AM
postfix mail server cant receive mail outside LAN shio Linux - Networking 2 10-05-2007 05:01 AM
Lan Plus 5b5 Video Monitor PingFloyd Linux - Hardware 0 08-16-2006 07:52 PM
Need LAN Monitor with graph like XP - help! AcerPowerT8400 Linux - Software 1 03-28-2005 08:19 AM
Wake-On-Lan or only closing monitor rayesteq Debian 1 11-29-2004 08:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration