hi all.. 

I having heavy trafic again :-(((( 29 k sec. last two hours.. 

I dont have any proxy�s running... 
the only thinsk thats open is port:

80
25
110

But i have some

NToskrnl listen on 139 , 138 , 137 ,135 

Im running w2000 


Right now i just puttede another ip on blacklist... 

Danm.. whats happening.. :( every time i put a ip on blacklist.. there goes some 
time.. there a new one and the trafic is raising :-( 

The Ntview.exe is only brining op the sambar windows.. but i can send this to ya all.. 


Proto  Lokal adresse          Fjernadresse           Status
TCP    p233:smtp              p233:0                 LISTENING
TCP    p233:http              p233:0                 LISTENING
TCP    p233:http              p233:0                 LISTENING
TCP    p233:pop3              p233:0                 LISTENING
TCP    p233:epmap             p233:0                 LISTENING
TCP    p233:microsoft-ds      p233:0                 LISTENING
TCP    p233:1025              p233:0                 LISTENING
TCP    p233:1026              p233:0                 LISTENING
TCP    p233:1790              p233:0                 LISTENING
TCP    p233:3858              p233:0                 LISTENING
TCP    p233:4899              p233:0                 LISTENING
TCP    p233:10500             p233:0                 LISTENING
TCP    p233:10501             p233:0                 LISTENING
TCP    p233:10502             p233:0                 LISTENING
TCP    p233:http              p233:2820              TIME_WAIT
TCP    p233:netbios-ssn       p233:0                 LISTENING
TCP    p233:netbios-ssn       P800:2315              ESTABLISHED
TCP    p233:7323              p233:0                 LISTENING
TCP    p233:http              p508BB7A7.dip.t-dialin.net:1372  ESTABLIS
TCP    p233:http              mailgw5.gedas.de:40972  ESTABLISHED
TCP    p233:http              pD4B9DFF7.dip.t-dialin.net:4162  FIN_WAIT
TCP    p233:netbios-ssn       p233:0                 LISTENING
TCP    p233:1790              64.12.24.214:5190      ESTABLISHED
UDP    p233:epmap             *:*
UDP    p233:microsoft-ds      *:*
UDP    p233:1027              *:*
UDP    p233:39213             *:*
UDP    p233:1042              *:*
UDP    p233:netbios-ns        *:*
UDP    p233:netbios-dgm       *:*
UDP    p233:isakmp            *:*
UDP    p233:netbios-ns        *:*
UDP    p233:netbios-dgm       *:*
UDP    p233:isakmp            *:*

thanks.. 

----- Original Message ----- 
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, August 16, 2002 3:33 PM
Subject: [sambar] Heavy trafic {02}


> Check what proxy ports you have open.. If you have some open, make sure you are 
>restricting the acceptproxy in security.ini to only your internal ip addresses.. 
>Also, if your running a server ie; win2k or winnt you can run the ntview.exe in the 
>/bin directory.. This will let you watch all the traffic.. You just might have people 
>using your server as a gateway.
> 
> Danny
> 
> 
> On 16/Aug/2002 11:13:51, Niels Poulsen wrote:
> > Hi all..
> I got a lot of heavy trafic to my sambar server... But if i look at the sambar 
>screen i cant see any connection active... 
> In my Sygate firewall Pro i can see sambar is sending 28 - 40 k out countiunsly and 
>are recieving about 2.0 to 3.4 K if i shot down the sambar program .. my Firewall 
>dont register any trafic.. 
> Any one who can help me... My server is running very slow
> Niels
> -------------------------------------------------------
> To unsubscribe please go to <A TARGET="_blank" 
>HREF="http://www.sambar.ch/list/";>http://www.sambar.ch/list/</A>
> 
> 
> -------------------------------------------------------
> To unsubscribe please go to http://www.sambar.ch/list/
> 
> 
> 
> 
> 
-------------------------------------------------------
To unsubscribe please go to http://www.sambar.ch/list/



Reply via email to