Такой вопрос, что это может быть?Может ли быть это вирус?
Смотрю просто tcpdump'ом.
Этот блок вылазит каждые ХХсекунд, и только от одного клиента.
tcpdump -i vr1 -n host 10.11.28.205
Показывает только этот блок и всё...сново и сново
23:40:14.225746 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 253
23:40:14.229033 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 271
23:40:14.236426 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 325
23:40:14.240236 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 317
23:40:14.245402 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 247
23:40:14.250385 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 289
23:40:14.274122 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 321
23:40:14.276039 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 267
23:40:14.278111 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 319
23:40:14.281983 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 313
23:40:14.294331 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 245
23:40:14.296394 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 288
23:40:14.298471 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 318
Так же:
# tcpdump -i vr1 -n host 10.11.28.205
tcpdump: WARNING: vr1: no IPv4 address assigned
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on vr1, link-type EN10MB (Ethernet), capture size 96 bytes
00:01:51.288032 arp who-has 10.11.28.205 tell 10.11.25.227
00:01:51.291948 arp who-has 10.11.25.227 (0a:0b:0a:0b:0a:0b) tell 10.11.28.205
00:01:51.292261 arp reply 10.11.25.227 is-at 00:16:d3:63:c1:e5
00:01:51.292293 arp reply 10.11.28.205 is-at 00:1b:11:6b:3c:c7
00:01:51.292573 IP 10.11.28.205.1900 > 10.11.25.227.1636: UDP, length 323
00:01:51.292778 IP 10.11.25.227.1640 > 10.11.28.205.5678: S 2115773503:2115773503(0) win 16384 <mss 1460,nop,nop,sackOK>
00:01:51.294861 IP 10.11.28.205.5678 > 10.11.25.227.1640: S 12376511:12376511(0) ack 2115773504 win 8192 <mss 1456>
00:01:51.295920 IP 10.11.25.227.1640 > 10.11.28.205.5678: . ack 1 win 17472
00:01:51.322769 IP 10.11.25.227.1640 > 10.11.28.205.5678: P 1:217(216) ack 1 win 17472
00:01:51.324561 IP 10.11.28.205.5678 > 10.11.25.227.1640: . ack 217 win 7976
00:01:51.976847 IP 10.11.28.205.5678 > 10.11.25.227.1640: P 1:120(119) ack 217 win 8192
00:01:51.979785 IP 10.11.28.205.5678 > 10.11.25.227.1640: . 120:1520(1400) ack 217 win 8192
00:01:51.981671 IP 10.11.25.227.1640 > 10.11.28.205.5678: . ack 1520 win 17472
00:01:51.982605 IP 10.11.28.205.5678 > 10.11.25.227.1640: . 1520:2976(1456) ack 217 win 8192
00:01:52.148641 IP 10.11.25.227.1640 > 10.11.28.205.5678: . ack 2976 win 17472
00:01:52.151970 IP 10.11.28.205.5678 > 10.11.25.227.1640: FP 2976:3003(27) ack 217 win 8192
00:01:52.152643 IP 10.11.25.227.1640 > 10.11.28.205.5678: . ack 3004 win 17445
00:01:52.747558 IP 10.11.25.227.1640 > 10.11.28.205.5678: R 217:217(0) ack 3004 win 0
00:01:54.586767 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 253
00:01:54.590024 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 271
00:01:54.597329 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 325
00:01:54.601076 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 317
00:01:54.610308 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 247
00:01:54.624106 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 289
00:01:54.635031 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 321
00:01:54.652748 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 267
00:01:54.660014 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 319
00:01:54.663686 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 313
00:01:54.666845 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 245
00:01:54.670320 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 288
00:01:54.674211 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 318
00:02:14.571589 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 253
00:02:14.571830 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 271
00:02:14.572158 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 325
00:02:14.572654 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 317
00:02:14.572980 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 247
00:02:14.573457 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 289
00:02:14.575030 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 321
00:02:14.576318 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 267
00:02:14.576668 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 319
00:02:14.578218 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 313
00:02:14.579307 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 245
00:02:14.579996 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 288
00:02:14.581136 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 318
00:02:34.578742 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 253
00:02:34.596383 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 271
00:02:34.615952 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 325
00:02:34.623117 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 317
00:02:34.623459 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 247
00:02:34.623947 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 289
00:02:34.624425 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 321
00:02:34.624752 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 267
00:02:34.625338 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 319
00:02:34.625681 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 313
00:02:34.626156 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 245
00:02:34.626630 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 288
00:02:34.627110 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 318
00:02:59.097898 arp who-has 10.11.27.227 (0a:0b:0a:0b:0a:0b) tell 10.11.28.205
00:02:59.098177 arp reply 10.11.27.227 is-at 00:13:8f:2d:1a:ea
00:02:59.100735 IP 10.11.28.205.1900 > 10.11.27.227.3715: UDP, length 323
00:03:02.117659 IP 10.11.28.205.1900 > 10.11.27.227.3715: UDP, length 323
00:03:05.118034 IP 10.11.28.205.1900 > 10.11.27.227.3715: UDP, length 323
00:03:14.584569 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 253
00:03:14.585179 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 271
00:03:14.585530 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 325
00:03:14.586770 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 317
00:03:14.597938 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 247
00:03:14.603635 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 289
00:03:14.603980 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 321
00:03:14.609253 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 267
00:03:14.609616 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 319
00:03:14.609945 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 313
00:03:14.610256 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 245
00:03:14.610591 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 288
00:03:14.610918 IP 10.11.28.205.1900 > 239.255.255.250.1900: UDP, length 318
|