but nothing stops it happening. the first cronjob doesn't restore the
rules, but the script does.
How can I find out what program is doing this? This surely counts as
malicious activity. The only difference between this host and
several others (all running daedalus) is that it is running some debian
edu packages.
At the moment I am 'watching' iptables -L and trying to see it using
top, but I'd prefer a log output so I can post it here as this must be
of general interest.