Hi guys,
I really love your work on amule. I know some nice series and I am downloading them with this app. I use it for about half an year.
Bat few days ago, my provider asked me, what am I sending to destination port 25 and IP adress 210.58.165.32. But I dont know. I use Kmail for sending emails and my smtp server is 192.168.1.1.
So I tried dropp every packet send from my box to port 25 except to destination IP of my smtp server. OK?
In /var/log/messages I can see now something like this:
Nov 15 06:47:56 radfoj kernel: DROPPED IN= OUT=eth0 SRC=192.168.50.13 DST=210.58.165.32 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=1491 DF PROTO=TCP SPT=2533 DPT=25 SEQ=1688180444 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40101040201030300)
In that time, amule was on. I stopped it about in 6:50. PC was still up and i start amule again in 17:30. And what the hell .... in log again :
Nov 15 17:35:23 radfoj kernel: DROPPED IN= OUT=eth0 SRC=192.168.50.13 DST=210.58.165.32 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=7141 DF PROTO=TCP SPT=2320 DPT=25 SEQ=4014174419 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40101040201030300)
12 x something like this.
When amule wass off, there isn't any dropped packet to port 25. And I am sure, that next dropp will come in next 0.5 - 3 hours.
Is there somebody, who can help me with this? I dont anderstand, what it is. I tried tcpdump and ethereal to capture packet on eth0 and port 25 .. but there was nothing about the source process of it.
I am using Mandrakelinux, I have private IP adress. I tried some tests for rootkins. Nothing. Please, I want know, whats going on. I am not good in English, so be patient.
I dont want to do disgrace to GNU/Linux.
Thanks a lot. By