Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
security breach? [solved]
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Wallsandfences
Guru
Guru


Joined: 29 Mar 2010
Posts: 378

PostPosted: Sun Dec 03, 2017 2:30 pm    Post subject: security breach? [solved] Reply with quote

Hi,
An hour ago I started my box. I'm running the profile change induced updates at the moment.

My hardware monitor shows, that my box uploaded 500MB at a more or less constant rate of 180Kib/sec during this hour.

I have no uploads running. So I think something strange is going on. How would you proceed from here?

R.


Last edited by Wallsandfences on Sun Dec 03, 2017 5:31 pm; edited 1 time in total
Back to top
View user's profile Send private message
roboto
Apprentice
Apprentice


Joined: 15 Feb 2017
Posts: 156
Location: My IP address.

PostPosted: Sun Dec 03, 2017 3:36 pm    Post subject: Reply with quote

What network service are you using?

I've had experience with DHCP constantly sending packets to 127.0.0.1.

If you have wireshark installed, then you can see where your packets are going. If they're going to 127.0.0.1, then you're fine. If they're going to a different and unfamiliar IP address, then something's up.
_________________
Answers please.

The true hater of man expects nothing from him and is indiscriminate to his works.
-Ayn Rand
Quote:
Dude. Minus 30 credibility points.

Yep
Back to top
View user's profile Send private message
Wallsandfences
Guru
Guru


Joined: 29 Mar 2010
Posts: 378

PostPosted: Sun Dec 03, 2017 5:17 pm    Post subject: Reply with quote

I use NetworkManager

Great tip re wireshark, it shows that the traffic goes to 224.0.0.56

I recall that‘s reserved, so not sure what that tells me...
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 54237
Location: 56N 3W

PostPosted: Sun Dec 03, 2017 5:24 pm    Post subject: Reply with quote

Wallsandfences,

That's 224.0.0.37-224.0.0.68 zeroconfaddr according to iana
Your box is multicasting something.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Wallsandfences
Guru
Guru


Joined: 29 Mar 2010
Posts: 378

PostPosted: Sun Dec 03, 2017 5:30 pm    Post subject: Reply with quote

Ok found it: multicast/rtp was active in pulseaudio. Switching it off solved the issue
Back to top
View user's profile Send private message
Ant P.
Watchman
Watchman


Joined: 18 Apr 2009
Posts: 6920

PostPosted: Sun Dec 03, 2017 5:30 pm    Post subject: Reply with quote

(edit: too slow, but might be useful for someone else)
Run lsof -ni (as root) and it should show what program's sending to that IP.
Back to top
View user's profile Send private message
Wallsandfences
Guru
Guru


Joined: 29 Mar 2010
Posts: 378

PostPosted: Sun Dec 03, 2017 7:31 pm    Post subject: Reply with quote

Ant P., your reply is still helpful, thanks!
R.

the other posters, thanks as well!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum