LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 09-04-2003, 01:09 PM   #1
zovres
Member
 
Registered: Sep 2002
Posts: 184

Rep: Reputation: 30
monitor and check what goes through pop3/imap


I would like to store in a file everything that goes through my pop3/imap/smtp server and run a string search in this file. the string search will be easy but I have no idea on how to have everything going in a file (or 3 files for each server)

anyone have an idea?

thx
 
Old 09-04-2003, 01:24 PM   #2
usernamenumber
Member
 
Registered: Sep 2003
Location: Somerville, MA
Distribution: Fedora/RHEL currently. Red Hat, Slackware, Debian, SuSe and Mandrake at other times
Posts: 104

Rep: Reputation: 15
Unless I've misunderstood you, either ethereal or snort could be used to do this. You'd probably want to go with Snort since it's command-line based and can run in the background less intrusively than ethereal. Snort can store (iirc) the entire contents of the packets it 'hears' either in one ASCII text file, multiple ASCII files (sorted by src addr, dst addr and dst port) or one big binary file, which is good for high-traffic sites since it stores the data more efficiently. You can then just use grep to search the text files or open the binary dumpfile in tcpdump or ethereal.

Snort, however, doesn't come with rh so you'll have to go to snort.org to get it.
 
Old 09-04-2003, 03:29 PM   #3
zovres
Member
 
Registered: Sep 2002
Posts: 184

Original Poster
Rep: Reputation: 30
"Unless I've misunderstood you" -> yes I'm sorry for my poor english

well I'll give a try with snort thx for your advice
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
qmail - different between POP3-IMAP -- Please help me b:z Linux - General 1 06-14-2005 06:14 AM
pop3/imap client? Thinking Linux - Networking 2 05-06-2005 11:30 AM
a way to monitor pop3 ans imap zovres Linux - Networking 2 08-25-2003 11:30 PM
Question on Imap and Pop3 cojo Linux - Software 2 06-17-2003 09:51 AM
pop3 / imap daemon markus1982 Linux - Software 1 03-03-2003 03:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 09:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration