Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Yahoo and strange traffic.
Date: Sun, 15 Aug 2010 22:06:13
Message-Id: 201008152232.40568.michaelkintzios@gmail.com
In Reply to: [gentoo-user] Yahoo and strange traffic. by Dale
1 On Sunday 15 August 2010 21:34:33 Dale wrote:
2 > Hi folks,
3 >
4 > I been noticing the past few weeks that something is communicating with
5 > Yahoo at these addresses:
6 >
7 > cs210p2.msg.sp1.yahoo.com
8 >
9 > rdis.msg.vip.sp1.yahoo.com
10 >
11 > I thought it was Kopete getting some info, profile pics maybe, from the
12 > server. Thing is, it does this for a really long time. It is also
13 > SENDING data as well. I have no idea why it is doing this or what it is
14 > sending. I closed the Kopete app but the data still carries on. This
15 > "transfer" has been going for a while now and the only way I can stop it
16 > is to stop the network, wait a minute or two for it to time out and then
17 > restart the network.
18 >
19 > Anybody have any idea what the heck this is? Is Yahoo up to something?
20 > Some new security issue that I haven't heard of?
21
22 What does your netstat show with respect to ports being used and what does
23 tcpdump/tcpflow show? If it is Yahoo, you should see things that are relevant
24 and hopefully make sense.
25 --
26 Regards,
27 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature