I am Learning Sort (yea)
I am getting this traffic i wasnt 2 worried about it till i saw that my network was sending it.
bout every half hour 4 of these to 2 different address at 80 and 8080.
I am running smoothwall 2.0 with all patches
DSL with a 2wire modem (wireless off)
Snort reported (The 127 is my external ip address)
Date: 08/07 00:52:13 Name: (http_inspect) BARE BYTE UNICODE ENCODING
Priority: n/a Type: n/a
IP info: 127.0.0.1:2433 -> 206.188.170.209:80
References: none found
One IP was down the one above typed into firefox offered me a file to download i have the file it is machine code (pretty sure).
What bothers me most is during my learning curve i ended up reloading almost every box on my network. I did a trend micro scan on my surfing box and only found three cookies. I really dont think this is coming from my network but it would be nice to know for sure and to keep my logger quiet.
Thanks alot for all responses
J
