kensmithzzz
09-23-2003, 03:59 PM
Ever since the first day of Sobig.F, bandwidth graphs on my server at Fastservers.net have shown a big increase in incoming traffic. Previously, most of my traffic was outbound, as one would expect with a webserver. Now, incoming traffic is roughly double outgoing.
Poking around today with tcpdump, I see lots of 'arp who-has' traffic. I'm seeing more than 200 of these per second, and I'm wondering what's normal for arp packets.
I also ran 'arp -e', and see only 3 machines listed in the ARP cache on my machine.
Poking around today with tcpdump, I see lots of 'arp who-has' traffic. I'm seeing more than 200 of these per second, and I'm wondering what's normal for arp packets.
I also ran 'arp -e', and see only 3 machines listed in the ARP cache on my machine.
