LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 11-18-2008, 02:07 AM   #1
nic2
LQ Newbie
 
Registered: Aug 2004
Location: Johannesburg, South Africa
Distribution: ubuntu 10.4
Posts: 6

Rep: Reputation: 0
Assistance needed to investigate unauthorised download by unknown service


This morning I noticed that on my Ubuntu 8.10 machine that System Monitor is reporting downloads at approximately 25 to 60 KiB/s despite the fact that nothing is supposed to be downloading. Not knowing what exactly to look for, I have checked the services running using System Monitor and Top but did not notice anything strange.

I checked my Router and Session Table reflected connection to my machine's IP address on destination port 53 - is it possible that a UDP request/reply can have this result?

Could anybody assist me in trying to establish what process is responsible for the download and why this is happening? Any assistance in this regard will be greatly appreciated, thank you in advance.

Ps. Broadband connections are capped in South Africa (also very expensive) and at this rate I will use the bulk of my data bundle by the end of the day.

Last edited by nic2; 11-18-2008 at 02:52 AM. Reason: Found possible problem
 
Old 11-18-2008, 03:54 AM   #2
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
Hi.

Install and run Wireshark (formerly Ethereal) to see what the traffic really is.

Dave
 
Old 11-18-2008, 07:26 PM   #3
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,356

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
If you look at /etc/services, you'll find

domain 53/tcp # name-domain server
domain 53/udp

ie that's the DNS port and can be udp OR tcp (used if query is too large). Possibly someone is trying the exploit this: http://www.unixwiz.net/techtips/igui...-dns-vuln.html

HTH
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Assistance Needed! Yellow Dog 5.0.1 Download kgaouette Linux - Newbie 8 05-22-2007 07:44 AM
ndiswrapper assistance needed dresek Linux - Wireless Networking 6 06-02-2006 05:00 PM
PAM assistance needed pvs Linux - Security 4 03-16-2006 10:20 AM
Assistance needed dmerchantdest Linux - Software 2 06-23-2004 04:29 PM
Crypt assistance needed. liguorir Programming 1 05-10-2004 10:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 01:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration