Aron Smith <[EMAIL PROTECTED]> said: > I have been getting a *Lot8 of disk activity around 7:00 am > the output from dmesg looks something like this > -----------------------------------------------------------------Shorewall :net2all:DROP:IN=eth0 > OUT= MAC=00:07:95:fc:2d:40:00:90:1a:40:aa:4d:08:00 SRC=24.202.47.169 > DST=64.81.53.247 LEN=48 TOS=0x00 PREC=0x00 TTL=108 ID=30226 DF PROTO=TCP > SPT=2296 DPT=5554 WINDOW=64240 RES=0x00 SYN URGP=0 > Shorewall:net2all:DROP:IN=eth0 OUT= > MAC=00:07:95:fc:2d:40:00:90:1a:40:aa:4d:08:00 SRC=24.202.47.169 > DST=64.81.53.247 LEN=48 TOS=0x00 PREC=0x00 TTL=108 ID=30480 DF PROTO=TCP > SPT=2544 DPT=9898 WINDOW=64240 RES=0x00 SYN URGP=0 > Shorewall:net2all:DROP:IN=eth0 OUT= > MAC=00:07:95:fc:2d:40:00:90:1a:40:aa:4d:08:00 SRC=83.64.20.224 > DST=64.81.53.247 LEN=52 TOS=0x10 PREC=0x00 TTL=106 ID=11550 DF PROTO=TCP > SPT=4200 DPT=21 WINDOW=65535 RES=0x00 SYN URGP=0 > Shorewall:net2all:DROP:IN=eth0 OUT= > MAC=00:07:95:fc:2d:40:00:90:1a:40:aa:4d:08:00 SRC=83.64.20.224 > DST=64.81.53.247 LEN=52 TOS=0x10 PREC=0x00 TTL=106 ID=12990 DF PROTO=TCP > SPT=4200 DPT=21 WINDOW=65535 RES=0x00 SYN URGP=0 > Shorewall:net2all:DROP:IN=eth0 OUT= > MAC=00:07:95:fc:2d:40:00:90:1a:40:aa:4d:08:00 SRC=64.78.124.187 > DST=64.81.53.247 LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=1830 DF PROTO=TCP > SPT=4887 DPT=5000 WINDOW=64240 RES=0x00 SYN URGP=0 > [EMAIL PROTECTED] aronsmith]$ > -------------------------------------------------------------------------- ----------- > have I been hacked? > Thanks in advance > smitty
The log activity you posted doesn't indicate it. Those are all network packets that Shorewall dropped -- that didn't get in.. it's normal to have this activity, generated either by hackers checking for security holes or worms and whatnot. Asa
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________