I work for a program in a high school, and we are running an old xserve with 10.3 on it. The only services we use are AFP and web. The dept. of education asked us take our server down because as of 4/23/09, "It is talking to foreign countries... Traffic is constantly coming out, even now."
I've checked every log file possible and don't even see and spikes in bandwidth or anything out of the ordinary. I'm currently running macscan on it but it appears that will only show me tracking cookies. Is it possible we've been hacked? I would hate to have to erase and install and set everything back up but if I can't get help then I guess that's all I will be able to do. Hopefully somebody knows something about this.. Thanks.
I've checked every log file possible and don't even see and spikes in bandwidth or anything out of the ordinary. I'm currently running macscan on it but it appears that will only show me tracking cookies. Is it possible we've been hacked? I would hate to have to erase and install and set everything back up but if I can't get help then I guess that's all I will be able to do. Hopefully somebody knows something about this.. Thanks.