alright, what the f is this nonsense?

shwaipshwaip bluffin' with my muffin Icrontian
edited May 2011 in Science & Tech
Noticed I had way more active connections than I should. results of netstat -n :
attachment.php?attachmentid=28932&stc=1&d=1304411916

MSE tells me that I have no viruses, but does anyone know what this is?
wat.png 139.8K

Comments

  • kryystkryyst Ontario, Canada
    edited May 2011
    Based on that port range it looks like p2p connections.
  • ThraxThrax 🐌 Austin, TX Icrontian
    edited May 2011
    Specifically, BitTorrent.
  • MAGICMAGIC Doot Doot Furniture City, Michigan Icrontian
    edited May 2011
    Specifically, pr0n.
  • ThraxThrax 🐌 Austin, TX Icrontian
    edited May 2011
    Specifically, DV-- nevermind.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2011
    No bittorrent running (or even installed). Maybe some sort of chrome plugin that uses BT to distribute data? It seems unlikely to be BT if all the IPs are the same, too.
  • ardichokeardichoke Icrontian
    edited May 2011
    Actually, all the IPs are not the same... you just have small blocks of IPs that are the same. That's exactly what BitTorrent does.

    Shut down everything that you have open and run a netstat, see if it's still like that. If it is then you may have a problem. Otherwise start reopening programs one at a time until you find the culprit.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2011
    Everytime I use BT, it has 1 IP per port...and actually I tend to set up my torrent programs to use 1 port so I don't have to open up a bunch in my firewall.

    ed: plus they're all going to port 80.
  • ardichokeardichoke Icrontian
    edited May 2011
    that's only the listening port. Once a client contacts the listening port the actual connection is established on a different port so that the listening port isn't tied up for other connections. Generally speaking.

    Regardless, I suggested where to start troubleshooting. Take it or leave it.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2011
    Happens with all internet browsing, regardless of browser.
  • ardichokeardichoke Icrontian
    edited May 2011
    Well, it looks like those IPs (at least the ones that I noticed repeat the most) belong to Level3, Akamai Technologies and Amazon. You probably have sites open that are pulling data/libraries/something else that are hosted by them. Akamai Technologies also hosts a lot of distributed content (apparently) such as software updates, virus scanner updates, etc.
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited May 2011
    I'm seeing it with stuff like browsing icrontic as well:
      TCP    192.168.1.106:55763    69.167.168.132:http
      TCP    192.168.1.106:55765    69.167.168.132:http
      TCP    192.168.1.106:55766    69.167.168.132:http
      TCP    192.168.1.106:55767    69.167.168.132:http
      TCP    192.168.1.106:55768    69.167.168.132:http
      TCP    192.168.1.106:55771    69.167.168.132:http
      TCP    192.168.1.106:55779    69.167.168.132:http
      TCP    192.168.1.106:55782    74:http
      TCP    192.168.1.106:55783    69.167.168.132:http
      TCP    192.168.1.106:55789    69.167.168.132:http
      TCP    192.168.1.106:55790    69.167.168.132:http
      TCP    192.168.1.106:55791    69.167.168.132:http
      TCP    192.168.1.106:55792    69.167.168.132:http
      TCP    192.168.1.106:55793    69.167.168.132:http
      TCP    192.168.1.106:55795    69.167.168.132:http
      TCP    192.168.1.106:55796    69.167.168.132:http
      TCP    192.168.1.106:55797    69.167.168.132:http
      TCP    192.168.1.106:55798    69.167.168.132:http
      TCP    192.168.1.106:55799    69.167.168.132:http
      TCP    192.168.1.106:55807    69.167.168.132:http
      TCP    192.168.1.106:55808    69.167.168.132:http
    

    (that's icrontic's IP, at least according to my interwibbles)
  • ardichokeardichoke Icrontian
    edited May 2011
    Yes that is Icrontic's IP. As to why you're opening multiple connections... depending on your browser it's probably just a feature to speed up page loading. I believe Firefox calls it http pipelining. There's also HTTP keepalives which keep connections open between page loads to speed up response time and multiple other tricks that could be causing multiple connections to stay open. If you have the IC IRC page open that's probably also causing some of it.
  • LincLinc Owner Detroit Icrontian
    edited May 2011
    Ever seen how many HTTP requests it takes to load Icrontic? It makes me sad.
  • ardichokeardichoke Icrontian
    edited May 2011
    Yeah, I just watched that.... and shuddered.
Sign In or Register to comment.