<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>detective work... - Computer Forensics - tribe.net</title>
    <link>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44?format=rss</link>
    <description>Tribe.net. Local Connections</description>
    <item>
      <title>Re: detective work...</title>
      <link>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#6fc9b645-6110-443f-a88a-2178784d5837</link>
      <description>I suggest findng a packet sniffer for a mac (perhaps ettercap has a mac port) and actually seeing what traffic is passing through.&#xD;
&#xD;
I would be willing to look at the packet capture if you manage to get that far.&#xD;
&#xD;
I don't look at this tribe frequently, so if you do that, make sure you send me a private message.</description>
      <pubDate>Sun, 31 Oct 2004 02:13:37 GMT</pubDate>
      <guid isPermaLink="false">http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#6fc9b645-6110-443f-a88a-2178784d5837</guid>
      <dc:creator>$item.owner.firstName</dc:creator>
      <dc:date>2004-10-31T02:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: detective work...</title>
      <link>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#b878d597-0c63-41b1-aff2-8ebfab0a8bb0</link>
      <description>If you had a PC, I'd suggest Sygate Personal Firewall Pro.  Let's you intercept data packets.&#xD;
&#xD;
Sorry, don't know Mac firewall products.</description>
      <pubDate>Fri, 29 Oct 2004 23:06:29 GMT</pubDate>
      <guid isPermaLink="false">http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#b878d597-0c63-41b1-aff2-8ebfab0a8bb0</guid>
      <dc:creator>Genghis "Doh!"</dc:creator>
      <dc:date>2004-10-29T23:06:29Z</dc:date>
    </item>
    <item>
      <title>detective work...</title>
      <link>http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#c2abaaac-a90d-4895-a9d9-f2f0f04f67c3</link>
      <description>Hi, I've been involved with some strange people. I won't go into the specifics, but, I run a Mac and I can close my Internet connection (DSL) and whenever I open certain applications, I see activity on my modem. All my IP apps show there is no connection, but certain programs seem to be able to send info anyway. When I do have the connection open, every 30 seconds or so, I show activity on my modem. I've checked all the settings I know of and none are set to "keep connection open" so there's no reason my machine should be sending packets.&#xD;
I'd really like to be able to figure out who is getting this info, but without their knowledge.&#xD;
I don't have a firewall installed because I want to find out what's happening without blocking these guys from my computer.&#xD;
Any suggestions?</description>
      <pubDate>Fri, 29 Oct 2004 23:02:39 GMT</pubDate>
      <guid isPermaLink="false">http://computerforensics.tribe.net/thread/418b8608-0e2e-493e-93c7-4cd049e21e44#c2abaaac-a90d-4895-a9d9-f2f0f04f67c3</guid>
      <dc:creator>Philen, Larry</dc:creator>
      <dc:date>2004-10-29T23:02:39Z</dc:date>
    </item>
  </channel>
</rss>



