Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Monitoring traffic to server via different ports

Status
Not open for further replies.

datadan

IS-IT--Management
Joined
Jul 22, 2002
Messages
283
Location
US
I run an IMAP server. (RH9/postfix/courrier).

Some computers are infected with a virus that uses its own SMTP engige to spew garbage. I am trying to isolate which computers are infected. My thought:

People should be connected to IMAP via port 143 or port 80/8080. SMTP is on port 25.

If I can isolate what traffic is comming to port 25 by IP I can then nail the bastard....

Does this sound reasonable? Ideas on tools I can use?
Thanks,
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top