irc웜일 가능성이 큽니다..
tcpdump같은 네트웍 어날라이저 툴을 사용해서 패킷 데이타를 보시기 바립니다.
irc웜일것 같군요^^;;
맥주소를 추적해 보심이 좋을듯..
: iptraf를 통해 내부 네트웍을 모니터해보니까..
:
: │┌140.148.12.88:1857 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0 │
: │┌140.148.12.89:1177 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0 │
: │┌140.148.12.90:1270 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0 │
: │┌140.148.12.91:1469 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0 │
: │┌140.148.12.92:1558 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0 │
: │┌140.148.12.93:1905 = 1 40 S--- eth0 │
: │└209.126.200.139:6667 = 0 0 ---- eth0
:
: 라고 나오네요.. 88 89 90 91 92 라는걸로 봐서는 누가 루틴을 돌리는거 같은데..
:
: 또한 문제는 140.148.12.x 와 209.126.200.139 는 저희랑 전혀 상관 없는 주소 입니다..
:
: 이 패킷이 라우터 바깥으로 나가는거 같지도 않고요..
:
: 신종 바이러스 일까요? +_+
:
:
: ps> 이 질문은 http://home.ahnlab.com/community/virus/bbs_view.jsp?p_bid=8&p_pagecnt=1&p_seq=83764 에 동시에
: 올라간 질문입니다. --
: we needa check the interior of the system who cares about only one culture
: and that is why we gotta take the power back - TAKE THE POWER BACK : RATM
:
: <img src='http://myhome.hanafos.com/~poorpuppet/undercon/smash.gif'>오늘도 삽질 내일도 삽질