Hi,
you can use network monitoring tools to investigate this. You might like to start with something simple like nethogs (universe repository) or for extremely detailed information you could use wireshark (also in the universe repository).
HTH,
Evo2.
PS. As frankbell says this is unlikely to be an exploit of any sort, just normal network traffic.
|