Smark wrote:
I was using an abnormally high (for me) ammount of bandwidth for a few days in a row. Using ntop I found that 99% of it was HTTP so I check my Apache logs. Turned out 90% of my HTTP traffic was going to brazil. I don't know anyone in brazil and they really dont need to be donloading random files so I used IP tables and blocked most of the traffic from .br domains. Traffic immediately went down to normal.
Check your box. People usually don't just download random files. Don't be surprised if you find porn or warez on it, in which case someone got in.