Hi everyone!

I have a network setup such that my router will only throw dest port 80 & 8080 traffic to my squid server.
Squid is listening to port 80 and 8080 only. I've got an acl that deny the CONNECT method for being used for all ports except 443.


When I do a netstat I found out that:

myserverip:44271 202.103.8.114:4365

where 203.103.8.114 is ftp1.tvdown.com

The strange thing is that I cannot see any mention of this IP or domain inside access.log.

Is there a possibility that the server is compromise?

_________________________________________________________________
Take a break! Find destinations on MSN Travel. http://www.msn.com.sg/travel/



Reply via email to