pppplus
Verified User
- Joined
- Dec 19, 2008
- Messages
- 526
Checking logs this morning, I send a lot of files like this :
These IP appears a lot of times : 208.83.137.117 and 208.83.137.118
So it seem that a website send date to these IPs, known to spam forum.
How to find which file/website do this ?
Thanks for your help
Code:
kernel: Firewall: *TCP_OUT Blocked* IN= OUT=eth0 SRC=94.23.246.189 DST=208.83.137.117 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=33114 DF PROTO=TCP SPT=50842 DPT=2703 WINDOW=14600 RES=0x00 SYN URGP=0
These IP appears a lot of times : 208.83.137.117 and 208.83.137.118
So it seem that a website send date to these IPs, known to spam forum.
How to find which file/website do this ?
Thanks for your help