Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 3rd February 2011, 08:32 PM
liderbug Offline
Registered User
 
Join Date: Feb 2005
Posts: 124
linuxfirefox
Possible hidden network traffic

Starting here because I don't where else to start. We have a 12M Qwest DSL line, PK5000. There is my computer, Linux FC13, my wife's computer M$ W7. I can run the Qwest DSL Speed test and get 10+ (ok, I'm getting shortchanged but I'll take that up with them). After a minute or two when my wife boots her computer she starts eating up 40% of the bandwidth. Her light on the PK5000 is non-stop running. When I run the speed test I get 6.2 - step over and unplug her cable and I get 10.2. She has AVG, MalwareBytes and Windows Defender running but I'm concerned she's been hijacked and is pumping spam. My tcpdump shows a lot of sher.ssdp > 239.255.255.250.ssdp traffic. Google doesn't seem to think it's a big deal. And it seems that when her computer is in use the bandwidth is ok - then about a minute (or 2) later(idle) ... here we go again. I just loaded ettercap but so far it doesn't show what is causing here light to run so hard. Advise?
Thanks
Chuck
Reply With Quote
  #2  
Old 3rd February 2011, 08:57 PM
AndrewSerk Offline
Registered User
 
Join Date: Oct 2010
Posts: 879
linuxfedorafirefox
Re: Possable hidden network traffic

If you have two network cards in your F13 box you could put your F13 box between the DSL modem and your MS7 box and use wireshark to capture packets and see what is being transferred.
Reply With Quote
  #3  
Old 3rd February 2011, 09:02 PM
William Haller Online
Registered User
 
Join Date: Jul 2005
Age: 52
Posts: 1,013
linuxfedorakonqueror
Re: Possable hidden network traffic

Is it possible that at boot her computer is downloading all the new AVG, and the like updates as well as checking for W7 updates and is thus network intensive for a bit? I'd go with the gateway test Andrew Serk mentioned and run wireshark to see what is really going on.
Reply With Quote
  #4  
Old 4th February 2011, 08:34 AM
stevea's Avatar
stevea Offline
Registered User
 
Join Date: Apr 2006
Location: Ohio, USA
Posts: 8,300
linuxfedorafirefox
Re: Possible hidden network traffic

If you don't have a second enet ofr a hub (not switch), then put wireshark on the Win PC and "shark" the packets. You want to see what is happening.
__________________
None are more hopelessly enslaved than those who falsely believe they are free.
Johann Wolfgang von Goethe
Reply With Quote
  #5  
Old 5th February 2011, 02:10 AM
liderbug Offline
Registered User
 
Join Date: Feb 2005
Posts: 124
linuxfirefox
Re: Possible hidden network traffic

I think I've got it fixed - time will tell.

239.255.255.250 SSDP NOTIFY - the only traffic on the her box - over & over & over.....

1. Start Registry Editor (Regedt32.exe).
2. Locate and click the following key in the registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectPlayNA THelp\DPNHUPnP
3. On the Edit menu, click Add Value, and then add the following registry value:
Value name: UPnPMode
Data type: REG_DWORD
Value data: 2 ---- although another page said set to 0 so I did
4. Quit Registry Editor.

at least it "seems" to be a whole lot better.

Thanks for the wireshark - it did the trick.
Reply With Quote
Reply

Tags
hidden, network, traffic

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Automatically connecting to hidden Network doesn't work 666flashback666 Servers & Networking 1 3rd January 2011 02:51 AM
Is there a quick (one click) way connect to a *hidden* wireless network? HawkBoy Servers & Networking 3 29th August 2009 11:23 AM
Solved Network Manager WL100 hidden SSID VideoRoy Servers & Networking 3 14th January 2009 12:24 AM
F8: Network Manager + hidden SSID sc_3007 Servers & Networking 3 21st August 2008 10:15 AM
Slow network traffic / Network manager doesn't work MadVillain Servers & Networking 1 28th July 2008 03:53 PM


Current GMT-time: 02:47 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat