Red Squirrel
No Lifer
This is really messed up. At random, my LAN totally took a dive. It started with just the internet, so I figured it was maybe my p2p VM that started actually downloading stuff, but it was not that. Everything was just queing as usual (I have rediculous bad luck with p2p) so I just turned it off anyway. Still nothing. Resetted modem, switch, and router. Nothing.
So I decide to check my router's connections, and there are thousands and thousands of active connections to 203.7.*.*:22 from my smoothwall's outside interface. I shut down all VMs behind the smooothwall to rule out that its the VMs acting up. Still doing it. I do tcpdump and it just completly spams to those IPs. It's a minimum Linux distro built for a firewall so I really can't see how it would of been hijacked. That firewall is also behind a physical router, only port 22 is forwarded to it. (ironic...)
Not sure what else this was doing, but it was enough to take down my entire LAN, let alone just slow down the internet... Anyone ever hear of this happening?
So I decide to check my router's connections, and there are thousands and thousands of active connections to 203.7.*.*:22 from my smoothwall's outside interface. I shut down all VMs behind the smooothwall to rule out that its the VMs acting up. Still doing it. I do tcpdump and it just completly spams to those IPs. It's a minimum Linux distro built for a firewall so I really can't see how it would of been hijacked. That firewall is also behind a physical router, only port 22 is forwarded to it. (ironic...)
Not sure what else this was doing, but it was enough to take down my entire LAN, let alone just slow down the internet... Anyone ever hear of this happening?