<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>detective work... - Computer Forensics - tribe.net</title>
  <link rel="alternate" href="http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44?format=atom" />
  <subtitle>Tribe.net. Local Connections</subtitle>
  <entry>
    <title>Re: detective work...</title>
    <link rel="alternate" href="http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#6fc9b645-6110-443f-a88a-2178784d5837" />
    <author>
      <name>$item.owner.firstName</name>
    </author>
    <id>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#6fc9b645-6110-443f-a88a-2178784d5837</id>
    <updated>2004-10-31T02:13:37Z</updated>
    <published>2004-10-31T02:13:37Z</published>
    <summary type="html">I suggest findng a packet sniffer for a mac (perhaps ettercap has a mac port) and actually seeing what traffic is passing through.&#xD;
&#xD;
I would be willing to look at the packet capture if you manage to get that far.&#xD;
&#xD;
I don't look at this tribe frequently, so if you do that, make sure you send me a private message.</summary>
    <dc:creator>$item.owner.firstName</dc:creator>
    <dc:date>2004-10-31T02:13:37Z</dc:date>
  </entry>
  <entry>
    <title>Re: detective work...</title>
    <link rel="alternate" href="http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#b878d597-0c63-41b1-aff2-8ebfab0a8bb0" />
    <author>
      <name>Genghis "Doh!"</name>
    </author>
    <id>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#b878d597-0c63-41b1-aff2-8ebfab0a8bb0</id>
    <updated>2004-10-29T23:06:29Z</updated>
    <published>2004-10-29T23:06:29Z</published>
    <summary type="html">If you had a PC, I'd suggest Sygate Personal Firewall Pro.  Let's you intercept data packets.&#xD;
&#xD;
Sorry, don't know Mac firewall products.</summary>
    <dc:creator>Genghis "Doh!"</dc:creator>
    <dc:date>2004-10-29T23:06:29Z</dc:date>
  </entry>
  <entry>
    <title>detective work...</title>
    <link rel="alternate" href="http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#c2abaaac-a90d-4895-a9d9-f2f0f04f67c3" />
    <author>
      <name>Philen, Larry</name>
    </author>
    <id>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#c2abaaac-a90d-4895-a9d9-f2f0f04f67c3</id>
    <updated>2004-10-29T23:02:39Z</updated>
    <published>2004-10-29T23:02:39Z</published>
    <summary type="html">Hi, I've been involved with some strange people. I won't go into the specifics, but, I run a Mac and I can close my Internet connection (DSL) and whenever I open certain applications, I see activity on my modem. All my IP apps show there is no connection, but certain programs seem to be able to send info anyway. When I do have the connection open, every 30 seconds or so, I show activity on my modem. I've checked all the settings I know of and none are set to "keep connection open" so there's no reason my machine should be sending packets.&#xD;
I'd really like to be able to figure out who is getting this info, but without their knowledge.&#xD;
I don't have a firewall installed because I want to find out what's happening without blocking these guys from my computer.&#xD;
Any suggestions?</summary>
    <dc:creator>Philen, Larry</dc:creator>
    <dc:date>2004-10-29T23:02:39Z</dc:date>
  </entry>
</feed>



