[lug] outgoing port 220 exploit?

D. Stimits stimits at comcast.net
Sat Jan 17 22:44:28 MST 2004

Well, netstat seems to work only for existing tcp connects, or if it is 
run right at the instant of a connect attempt. What I have here is a 
period failed connect to outside port 220, it is blocked both on the 
local machine and on the bridge firewall, so it never gets beyond a SYN 
packet. I'm thinking what I need is a tcpdump. Only I'm having a problem 
with the tcpdump syntax. Can anyone tell me the syntax to use tcpdump to 
continuously dump info of any port 220 destination packets? And is there 
a way to give source application info the way netstat does with the 
-lenp argument?

D. Stimits, stimits AT comcast DOT net

PS: This only seems to show up when mozilla is running, but I have 
tested it far too little to know for sure yet.

