LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-06-2005, 05:11 PM   #1
edma
LQ Newbie
 
Registered: Jan 2005
Posts: 3

Rep: Reputation: 0
log_messenger


Hi, i´m new around here and i´m looking for help.
I have a debian firewall for my local company, it has at all 12 people working here.
I want to make a log of all the information that go through the messenger. I want to see the ip machines and users that use the Messenger..to keep that information in some way, to see th trafic for that port. How can I do that? Where will my log file stored?
Thanks for your help.
 
Old 01-06-2005, 05:27 PM   #2
Linux~Powered
Member
 
Registered: Jan 2004
Location: /lost+found
Distribution: Slackware 14.2
Posts: 849

Rep: Reputation: 33
You can use a program like snort
 
Old 01-07-2005, 04:56 AM   #3
edma
LQ Newbie
 
Registered: Jan 2005
Posts: 3

Original Poster
Rep: Reputation: 0
Ok, thanks for your help, but I use IPTABLES in my firewall and I want to keep in that way.
So I want to see the traffic information though messsenger port using iptables. Any suggestion?
Please, if someone knows anything about this give me a tip.
Thanks a lot
 
Old 01-07-2005, 08:33 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Iptables and Snort are two completely different entities that can be used together (iptables is a packet filter while Snort is a intrusion detection system).

If you just want to monitor a certain subset of traffic, either a certain protocol or from a specific host, try tcpdump/ethereal. There are also protocol-specifc sniffers like AIMSniff and dsniff. Also remember that in certain countries it's illegal to monitor employees internet transmissions without prior notification.

Last edited by Capt_Caveman; 01-07-2005 at 08:35 PM.
 
Old 01-08-2005, 08:04 AM   #5
edma
LQ Newbie
 
Registered: Jan 2005
Posts: 3

Original Poster
Rep: Reputation: 0
I don´t want to monitor, i just want to see the ip addres machines that access to the messenger, when, how many times, etc..., i ask then to use jabber the internal networking "messenger" but they still use the messenger to talk with friend. So i only want to report those events for the Microsoft Messenger, just that, and keep it in a log file.
I need a explicit help in this issue please. And one more question: how i choose the file to log those events?
Thanks!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration