Koozali.org: home of the SME Server

bandwidth hacked

mike mattos

bandwidth hacked
« on: November 24, 2003, 04:25:48 AM »
iptraf is showing lines as follows indicating usage of my external port.   No similar activity internally, but I have seen Windows file sharing programs do this in the past.  I've turned off Apache and Tomcat, also checked as a spam attack, wondered how to proceed next?

System is SME 55


│┌ppp-217-133-146-143.cust-adsl.ti:1800       >    2667    122750 -PA-   eth1  │
│└s207-219-125-122.on.hsia.telus.n:1824       >    2682  

FTP is off, so is TELNET, so I'm wondering where to look next

Thanks

Mike

Charlie Brady

Re: bandwidth hacked
« Reply #1 on: November 24, 2003, 06:54:19 PM »
mike mattos wrote:

> System is SME 55

Not recommended, as nobody is releasing security updates for 5.5.

> │┌ppp-217-133-146-143.cust-adsl.ti:1800      
> >    2667    122750 -PA-   eth1  │
> │└s207-219-125-122.on.hsia.telus.n:1824      
> >    2682

There is *nothing* you can do to stop sites sending you packets. As long as your machine doesn't reply, you cannot improve the situation. This is a fact of life on the Internet.

Charlie