here is a log created by wallwatcher and i scrubbed out all activity other than root-servers.net
from what i have seen this ida dos attach on those servers.
this sme server is a system that is running and the only ports going to it are 80 110 443 25 and maybe one other.
i will try to see what is happening at other locations
Charlie,
i do not do very much at all with this computer, basically i has been dormant in a sense.
i had worked with it very little and i was planning on using it as a email server sometime ago.
i place a few files on the server as just a backup to my computer many moons ago.
because i am now back to trying to figure out whether i want to use it as a email server i did updates from the server-manager.
maybe some computer attacked this server. i did not write down the when it did the update but it was about the time this all started.
i do not review logs very often, i had a employee going to myspace in a virtual machine that we use for accessing the internet.
i started monitoring the activity because i do not want any sites visited that do not have to do with business and the risk it brings on.
i am not sure whats happen but it would seem logical to first look at the updates if sme server is suppose to be a very secure sever.
in all honesty my admin password was not the most best.
i did some lookups on the internet and had seen quiet a few hits on "centos" and "root-server.net"
i will have to reinstall sme server soon, as i do not want to be the source of any bad things even if they do not damage my data or system.
but i wanted to see if i could identify the problem.
maybe i can some way show what addons i am running, it should be very few.
wallwatcher is free, but runs under windows.
i have wallwatcher running 3 locations with sme servers at those locations.
this is the first time and the only time i have seen any sme server doing outbound activity that did not seem write.
i do not like to bring problems to the table, but this is where i felt i should report it even if it did not come from updates
so that others can lookout for it too.
charlie thanks for the reply
i would not even mind giving you access to the server thru port 22 if you would like after i backup and erase any sensitive data.
the log has been cut down
i will trim it down after the discussion to reduce space used on the forum server
the server is attacking on port 53
""2008/06/09 07:57:20.32 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 45725""
""2008/06/09 07:58:16.02 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 44963""
""2008/06/09 07:58:16.02 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 15717""
""2008/06/09 07:58:16.02 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 9419""
""2008/06/09 07:58:16.02 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 62994""
""2008/06/09 07:58:16.02 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 63906""
""2008/06/09 08:00:07.56 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 4050""
""2008/06/09 08:00:07.56 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 52751""
""2008/06/09 08:00:07.56 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 12618""
""2008/06/09 08:00:07.56 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 6547""
""2008/06/09 08:00:41.81 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 38218""
""2008/06/09 08:01:34.31 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 23256""
""2008/06/09 08:01:34.31 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 14024""
""2008/06/09 08:01:34.31 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 60652""
""2008/06/09 08:01:34.31 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 35238""
""2008/06/09 08:01:46.56 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 61077""
""2008/06/09 08:02:46.48 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 63718""
""2008/06/09 08:02:46.48 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 23327""
""2008/06/09 08:03:46.56 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 27340""
""2008/06/09 08:06:46.53 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 1176""
""2008/06/09 08:08:46.50 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 62994""
""2008/06/09 08:08:46.50 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 7140""
""2008/06/09 08:11:46.57 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 40990""
""2008/06/09 09:04:46.10 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 63906""
""2008/06/09 09:05:46.12 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 12618""
""2008/06/09 09:05:46.12 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 35988""
""2008/06/09 09:05:46.12 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 45827""
""2008/06/09 09:06:46.09 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 61077""
""2008/06/09 09:06:46.09 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 6547""
""2008/06/09 09:06:46.09 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 32559""
""2008/06/09 09:07:46.12 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 62853""
""2008/06/09 09:07:46.12 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 60652""
""2008/06/09 09:08:46.17 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 40218""
""2008/06/09 09:08:46.17 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 9419""
""2008/06/09 09:09:46.14 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 6929""
""2008/06/09 09:09:46.14 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 34479""
""2008/06/09 09:12:46.14 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 63718""
""2008/06/09 09:14:45.33 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 7140""
""2008/06/09 09:14:45.33 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 35988""
""2008/06/09 09:14:45.33 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 41514""
""2008/06/09 09:15:48.52 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 56151""
""2008/06/09 09:16:48.48 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 50099""
""2008/06/09 09:16:48.48 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 62853""
""2008/06/09 09:17:45.16 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 27340""
""2008/06/09 09:17:45.18 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 40990""
""2008/06/09 09:18:53.51 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 52495""
""2008/06/09 09:18:53.52 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 61604""
""2008/06/09 09:19:53.50 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 32559""
""2008/06/09 09:20:53.43 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 6627""
""2008/06/09 09:24:57.38 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 45725""
""2008/06/09 10:13:29.95 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 28737""
""2008/06/09 10:15:30.03 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 45827""
""2008/06/09 10:15:30.03 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 53007""
""2008/06/09 10:16:29.96 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 4321""
""2008/06/09 10:17:30.05 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 34479""
""2008/06/09 10:18:22.19 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 1901""
""2008/06/09 10:18:22.19 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 52495""
""2008/06/09 10:18:22.19 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 61838""
""2008/06/09 10:18:22.19 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 40218""
""2008/06/09 10:18:22.19 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 64664""
""2008/06/09 10:19:36.16 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 50099""
""2008/06/09 10:21:36.13 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 53622""
""2008/06/09 10:22:22.69 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 6929""
""2008/06/09 10:26:37.48 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 64664""
""2008/06/09 10:27:37.49 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 54996""
""2008/06/09 10:33:38.34 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 28737""
""2008/06/09 11:21:37.79 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 33294""
""2008/06/09 11:23:37.79 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 4321""
""2008/06/09 11:24:12.79 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 41514""
""2008/06/09 11:24:12.79 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 10032""
""2008/06/09 11:24:12.79 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 61838""
""2008/06/09 11:24:12.79 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 19512""
""2008/06/09 11:24:12.79 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 42405""
""2008/06/09 11:24:48.15 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 61604""
""2008/06/09 11:24:48.15 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 56151""
""2008/06/09 11:24:48.15 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 12647""
""2008/06/09 11:25:27.61 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 1901""
""2008/06/09 11:25:27.61 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 42549""
""2008/06/09 11:25:58.00 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 46001""
""2008/06/09 11:26:36.53 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 53007""
""2008/06/09 11:26:36.53 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 22840""
""2008/06/09 11:26:36.53 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 53622""
""2008/06/09 11:26:36.53 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 31111""
""2008/06/09 11:28:01.53 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 6627""
""2008/06/09 11:29:01.46 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 22107""
""2008/06/09 11:30:01.47 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 33294""
""2008/06/09 11:30:01.47 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 47408""
""2008/06/09 11:31:01.46 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 64526""
""2008/06/09 11:33:01.45 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 42549""
""2008/06/09 11:43:01.13 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 12647""
""2008/06/09 11:45:01.11 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 10032""
""2008/06/09 12:32:01.36 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 14808""
""2008/06/09 12:33:01.37 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 20599""
""2008/06/09 12:33:01.37 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 22107""
""2008/06/09 12:33:19.58 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 64526""
""2008/06/09 12:33:19.59 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 19512""
""2008/06/09 12:33:19.59 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 51508""
""2008/06/09 12:34:06.91 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 31111""
""2008/06/09 12:34:06.92 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 59659""
""2008/06/09 12:34:06.92 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 60232""
""2008/06/09 12:34:06.92 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 22711""
""2008/06/09 12:35:06.92 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 22840""
""2008/06/09 12:35:06.92 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 16519""
""2008/06/09 12:35:06.92 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 42405""
""2008/06/09 12:35:06.94 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 15065""
""2008/06/09 12:36:06.89 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 46001""
""2008/06/09 12:36:06.89 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 31748""
""2008/06/09 12:37:54.89 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 17982""
""2008/06/09 12:37:54.89 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 14808""
""2008/06/09 12:37:54.89 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 15065""
""2008/06/09 12:38:20.86 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 7103""
""2008/06/09 12:39:20.80 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 54996""
""2008/06/09 12:41:30.40 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 31058""
""2008/06/09 12:41:30.40 B 255.255.255.255 f.root-servers.net 138 192.168.0.70 138""
""2008/06/09 12:45:30.48 B 255.255.255.255 f.root-servers.net 138 192.168.0.70 138""
""2008/06/09 12:53:30.45 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 20599""
""2008/06/09 13:06:59.27 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 21895""
""2008/06/09 13:07:53.46 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 22711""
""2008/06/09 13:07:53.46 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 51508""
""2008/06/09 13:07:53.46 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 36422""
""2008/06/09 13:07:53.46 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 63934""
""2008/06/09 13:08:05.04 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 62647""
""2008/06/09 13:09:04.98 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 16519""
""2008/06/09 13:10:04.99 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 31748""
""2008/06/09 13:10:04.99 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 7103""
""2008/06/09 13:10:04.99 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 47408""
""2008/06/09 13:11:04.99 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 19148""
""2008/06/09 13:11:04.99 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 19462""
""2008/06/09 13:11:04.99 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 20856""
""2008/06/09 13:12:04.98 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 2991""
""2008/06/09 13:13:54.22 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 59659""
""2008/06/09 13:13:54.22 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 31058""
""2008/06/09 13:13:54.22 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 17002""
""2008/06/09 13:13:54.22 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 39375""
""2008/06/09 13:16:04.95 O 192.58.128.30 j.root-servers.net 53 192.168.0.190 21895""
""2008/06/09 18:22:22.34 O 192.228.79.201 b.root-servers.net 53 192.168.0.190 60232""
""2008/06/09 18:25:22.23 O 192.112.36.4 g.root-servers.net 53 192.168.0.190 17982""
""2008/06/09 18:56:21.58 O 192.203.230.10 e.root-servers.net 53 192.168.0.190 36422""
""2008/06/09 18:56:21.58 O 128.63.2.53 h.root-servers.net 53 192.168.0.190 63934""
""2008/06/09 18:56:21.58 O 192.33.4.12 c.root-servers.net 53 192.168.0.190 62647""
""2008/06/09 18:58:21.48 O 128.8.10.90 d.root-servers.net 53 192.168.0.190 19148""
""2008/06/09 18:58:21.48 O 198.41.0.4 a.root-servers.net 53 192.168.0.190 19462""
""2008/06/09 18:59:21.46 O 193.0.14.129 k.root-servers.net 53 192.168.0.190 20856""
""2008/06/09 19:00:21.32 O 202.12.27.33 m.root-servers.net 53 192.168.0.190 2991""
""2008/06/09 19:01:33.16 O 192.36.148.17 i.root-servers.net 53 192.168.0.190 17002""
""2008/06/09 19:02:33.16 O 192.5.5.241 f.root-servers.net 53 192.168.0.190 39375""