Old 04-06-2010, 04:56 AM   #1 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,879
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default Weird traffic!

Hi,

I am observing some weird traffic on my home Untangle device.

I am running Jnettop and observing how:
195.54.109.58:50000 is talking to 233.33.194.35:10035 at 800 kb/s

But none of those networks are mine!
I can only see this traffic on the external interface if i switch to the internal i can't see anything matching.

the 195.54.109.58 is own by my ISP but it should not talk to my UT.

The only thing i can think of is that someone has hackt my apache and are now using it as a proxy.

What do you guys think?

I will capture the traffic and see whats in it.
WebFooL is offline  
Old 04-06-2010, 05:16 AM   #2 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,634
dwasserman is on a distinguished road
Default

Maybe 195.54.109.58 is a neighbor and your ISP is working over a sharing device misconfigured and jnettop can view?
dwasserman is offline  
Old 04-06-2010, 05:22 AM   #3 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,879
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Quote:
Originally Posted by dwasserman View Post
Maybe 195.54.109.58 is a neighbor and your ISP is working over a sharing device misconfigured and jnettop can view?
Possible.
The traffic is encoded/encrypted so i can't see whats in it

Will have to call them if its still there when i come home.. :P
WebFooL is offline  
Old 04-06-2010, 05:27 AM   #4 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,879
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Found it..
I have IPTV and the remote IP is the TV Server.
The IPTV dose not go over the Untangle box but some how it picks up the UDP traffic.

Will have to reconfigure my Switch..
WebFooL is offline  
Old 04-06-2010, 05:28 AM   #5 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,634
dwasserman is on a distinguished road
Default

Think this: either the origin or destination ip address are your ip.
Or is a sophisticated "man in the middle" attack or when running jnettop the interface go to some type of promiscous mode and view all traffic at next hop.
dwasserman is offline  
Old 04-06-2010, 05:31 AM   #6 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,634
dwasserman is on a distinguished road
Default

Quote:
Originally Posted by WebFooL View Post
Found it..
I have IPTV and the remote IP is the TV Server.
The IPTV dose not go over the Untangle box but some how it picks up the UDP traffic.

Will have to reconfigure my Switch..
But you own 195.54.109.58?
dwasserman is offline  
Old 04-06-2010, 05:43 AM   #7 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,879
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Nopp
I don't know if they have a own VLAN for the TV boxes in that case i might have 195.54.109.58
WebFooL is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:51 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2