After installing torsmo and having it update once per second I've noticed that eth0 always stay active downloading 1-2KB/s. What's that all about? Should it be that way ...or worse: Am I being hacked?
I don't run any services at all. And I've got shorewall proper configured. What other
ways are there to see what the traffic is? I don't have "ethereal".
Ok. I've ran ethereal and it turned out to be a lot of connections to some ARP protocol that were showing up in torsmo. I don't know anything about networks and suchs but does this just mean that it's my computer that checks back to the dhcp-server or samething similiar? In other words: is this harmless?
Its probably broadcast traffic is all. I wouldnt worry too much about it. ARP (address resolution protocol) maps Logical addresses (ip) to physical address (MAC). It works like this, say that host1 connects to a network and knows nothing except his MAC and his IP. He tries to ping host2. He will send out a broadcast message to asking everyone in his ip space hey - if you know this IP address please respond with your MAC. Host2 recognizes this and replies. Host1's ARP cache is then populated with the mapping. Thats kinda how ARP works.