Sharft 6
July 7th, 2011, 12:16 AM
For the last couple of weeks I have been trying to figure out what application is uploading and downloading 0-2KB/s. So far I have figured out that the ip and ports are random and nothing else.
I have tried looking through a huge list of processors (sudo ps -a) and killing a bunch of them but the traffic usage hasn't died down at all.
e.g.
transmission-da
mythtv-backend
mythfrontend
mythfrontend.real
vsftpd
httpd
smbd
srcds
I have tried ntop but that doesn't work.
I have tried iftop but that doesn't give me anything useful.
I have tried nmmap but again that doesn't bring up anything useful.
I have tried wireshark and whois but all that shows is the traffic is comming from and going to random ip addresses and ports. The only consistency is that the protocol is UDP.
I have tried netstat but that doesn't bring up anything useful either.
Those are just the tools I remember using. I have used more but obviously didn't get anywhere with them.
Does anybody have anymore ideas?
OS: mythbuntu 10.04
I have tried looking through a huge list of processors (sudo ps -a) and killing a bunch of them but the traffic usage hasn't died down at all.
e.g.
transmission-da
mythtv-backend
mythfrontend
mythfrontend.real
vsftpd
httpd
smbd
srcds
I have tried ntop but that doesn't work.
I have tried iftop but that doesn't give me anything useful.
I have tried nmmap but again that doesn't bring up anything useful.
I have tried wireshark and whois but all that shows is the traffic is comming from and going to random ip addresses and ports. The only consistency is that the protocol is UDP.
I have tried netstat but that doesn't bring up anything useful either.
Those are just the tools I remember using. I have used more but obviously didn't get anywhere with them.
Does anybody have anymore ideas?
OS: mythbuntu 10.04