October 15, 20178 yr Hi, i noticed today morning a high traffic from our unRaid server to external IP Addresses. When i checked the firewall log i noticed a lot of blocked traffic on port 389 and 139. if that would be a window machine i would be quite worried to got "Wanna Cry" but on unRaid/linux. is there any other explenation for this traffic? regards Matt
October 15, 20178 yr Port 139 is NETBIOS Session Service - Some Trojans use these ports to communicate Port 389 is LDAP Edited October 15, 20178 yr by Zonediver
October 16, 20178 yr Author 18 hours ago, Zonediver said: Port 139 is NETBIOS Session Service - Some Trojans use these ports to communicate Port 389 is LDAP yes right, i would understand if that would come from one of my windows PC on the network but from my unRaid server itself looks a bit odd to me.
October 18, 20178 yr Author On 10/16/2017 at 3:29 PM, Zonediver said: ...the only explanation could/would be a VM running on unraid... there are no VMs/Docker setup at all. that's why i start wondering whats going on. also the GUI is extremely slow. please find attached also me diagnostics file. ffaejeans01-diagnostics-20171018-1229.zip
Archived
This topic is now archived and is closed to further replies.