PS: I found out those multiple connects on port 80 are from worms not gnutella clients. After enabling port 80 connects from outside, I found in the httpd log MANY requests to start a file root.exe... so it's from code-red/nimda infected hosts, tells Google. |