Few hours short of noon today, I dialed in and got an IP from my ISP’s DHCP server. Before I could open up a terminal and execute fetchmail to fetch my e-mails, I noticed the two red lights on my modem blinking red and green. They were blinking fast. Seeing as nothing on the system had initiated any sort of connections, I suspected something was amiss. Frantically, I ran snort in IDS mode in one terminal, constantly monitoring the alerts file for any notifications, started tethereal in another terminal, and called up EtheRape to generate a dynamic, grahical model of network traffic my box was seeing.
I was shocked. More than hundred IPs were hitting me on port 6881. A quick grok of the /etc/nmap-services file against the port number 6881 turned nil. However, searching across Google, I found out port 6881 used by Bittorrent.
I captured a snapshot of one of my screens which was running the packet logging and network monitoring tools I just mentioned: wtf.png