Re: RE: Bizarre traffic
- From: "Ramez Hanna" <ramez.hanna@xxxxxxxxx>
- Date: Thu, 23 Feb 2006 20:56:17 +0200
you can use
netstat -naptu | grep -i established
this should show you all the connection going out and you will also
see which process is causing them
On 23 Feb 2006 13:44:16 -0000, selfinnoculation@xxxxxxxxx
<selfinnoculation@xxxxxxxxx> wrote:
I am not too sure if I can agree with you at this moment, David. It is indeed weird that traffic is only heading towards the HTTPS port.
Have you considered running a netmon service on that source machine to see which application is actually sending out requests for HTTPS? You might be able to nail the culprit there.
Good luck.
- Follow-Ups:
- Re: RE: Bizarre traffic
- From: Ansgar -59cobalt- Wiechers
- Re: RE: Bizarre traffic
- References:
- Re: RE: Bizarre traffic
- From: selfinnoculation
- Re: RE: Bizarre traffic
- Prev by Date: Increase in MS-SQL Probes
- Next by Date: announcement: reporting and mitigating botnets
- Previous by thread: Re: RE: Bizarre traffic
- Next by thread: Re: RE: Bizarre traffic
- Index(es):
Relevant Pages
|