Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
01-16-2006, 10:47 AM
|
#1
|
LQ Newbie
Registered: Nov 2005
Posts: 2
Rep:
|
Hard drive activity when online, is someone monitoring
Can anyone tell me why this happens? When I am on-line I see my dsl modem activity light flash a few times and then my hard drive starts reading and writing. It does this only when I am on-line, I turn off my router and the activity stops. netstat indicates no listening ports. I am using Suse 10.0 behind a router to a dsl connection. Running the standard Suse firewall with default setting. I believe I have all services turned off that I don't need. No servers needed or running. I just use my box for e-mail and web surfing.
How do I check out whats going on?
Am I too paranoid?
Thanks for your help and ideas.
|
|
|
01-16-2006, 10:52 AM
|
#2
|
LQ Newbie
Registered: Jan 2006
Posts: 4
Rep:
|
You could try to sniff the traffic with Ethereal while you are online.
Then you should see where the packets come from / where they go.
I guess it is only doing broadcasts, discovery messages, etc.
But the hdd activity confuses me
|
|
|
01-16-2006, 10:54 AM
|
#3
|
Senior Member
Registered: Sep 2005
Location: Out
Posts: 3,307
Rep:
|
Do you have a fixed IP?
Maybe you are getting old packets of P2P users.
Then your firewall logs the packets which could explain the disk usage.
It could be a process trying to update something.
What you could do in this case is install Ethereal.
Launch Ethereal, launch your connection, don't do anything, don't breathe and stop it after you have something.
Right click on one packet and choose "follow tcp stream" , you should see the text being sent/received.
|
|
|
01-16-2006, 03:06 PM
|
#4
|
Senior Member
Registered: Jan 2003
Location: Portland, OR USA
Distribution: Slackware, SLAX, Gentoo, RH/Fedora
Posts: 1,024
Rep:
|
Have you tried just running top, or ktop or whatever gnome's version of it is and seeing what processes are using the CPU?
|
|
|
01-16-2006, 03:52 PM
|
#5
|
Member
Registered: Oct 2004
Posts: 229
Rep:
|
Use ps aux to see all processes.
Use lsof to see all open files in your system. Usually a lot of libs will appear.
|
|
|
All times are GMT -5. The time now is 04:16 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|