From owner-freebsd-questions@FreeBSD.ORG Thu Jun 23 17:26:24 2005 Return-Path: X-Original-To: FreeBSD-questions@FreeBSD.org Delivered-To: FreeBSD-questions@FreeBSD.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5E05916A41C for ; Thu, 23 Jun 2005 17:26:24 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from pi.codefab.com (pi.codefab.com [199.103.21.227]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2C5AB43D48 for ; Thu, 23 Jun 2005 17:26:24 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from localhost (localhost [127.0.0.1]) by pi.codefab.com (Postfix) with ESMTP id 99F725F2D; Thu, 23 Jun 2005 13:26:23 -0400 (EDT) Received: from pi.codefab.com ([127.0.0.1]) by localhost (pi.codefab.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 33655-03; Thu, 23 Jun 2005 13:26:23 -0400 (EDT) Received: from [192.168.1.3] (pool-68-161-69-22.ny325.east.verizon.net [68.161.69.22]) by pi.codefab.com (Postfix) with ESMTP id 8305B5C0F; Thu, 23 Jun 2005 13:26:22 -0400 (EDT) Message-ID: <42BAF0BF.8000200@mac.com> Date: Thu, 23 Jun 2005 13:26:23 -0400 From: Chuck Swiger Organization: The Courts of Chaos User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8) Gecko/20050511 X-Accept-Language: en-us, en MIME-Version: 1.0 To: ruben@bloemgarten.demon.nl References: <20050623013109.EFAD843D1F@mx1.FreeBSD.org> In-Reply-To: <20050623013109.EFAD843D1F@mx1.FreeBSD.org> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 8bit X-Virus-Scanned: amavisd-new at codefab.com Cc: FreeBSD-questions@FreeBSD.org Subject: Re: stat running as www weirdness - genarting INCOMING traffic X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 23 Jun 2005 17:26:24 -0000 Ruben Bloemgarten wrote: > I’m seeing weirdness of stat opening up port 4000+ and generating/receiving > enormous amounts of incoming traffic i.e. 400Gb over a 24hour time > period.Does this sound familiar to anyone ? Thanks for any brain usage not > my own. Insufficient data. From which port(s) to which port(s), and are the IP addresses on the other side the same or a random range (which would imply your machine has been hacked and is scanning outwards). Showing a tcpdump of a few example connections would be really useful. -- -Chuck