Possible Duplicate:
My server's been hacked EMERGENCY
My Linux (CentOS 5.x) machine seem to have been attacked. Port scanning activities were traced to it. However, the ports (to be) scanned were only 8080. As a temporary measure, I have updated the iptables rules to drop all outbound traffic from the machine to port 8080.
However, 1. I would like to ascertain if indeed my machine has been compromised. 2. Also if it is really port scanning, would it be restricted to just a single port 8080? 3. And most importantly, should the machine be infected with some malware, causing the port scans, how please can I make it clean again.
Thanks