I got home yesterday to find my internet connection down. I called my ISP who told me that it had been closed by them since they had been getting a LOT of e-mail spam reports on my IP address the last two weeks or so.
These reports started coming on February 14th. That day I added a new domain do my bubba, installing wordpress for it.
The one shady thing I did during that installation was that I for a very short period of time chmod'ed the upload folder to 777 to see what user did the uploads through the wp admin. I then chmodd'ed the upload folder back and chown'ed the upload folder to that user.
I also added the new domain to bubbadomains in /etc/postfix (if that's where it's located

That's all that I can remember from that day.
So: Yesterday I turned all e-mail services off on my Bubba2 and told my ISP that they can safely turn my connection back on. They did. But as I re-connected the Bubba I saw the network traffic starting to take off. And the reason seems to be a file called y2kupdate that causes this. A line in the syslog says (over and over and over):
bubba /USR/SBIN/CRON[16436]: (www-data) CMD (tmp/lib/y2kupdate >/dev/null 2>&1)
When I saw this I just turned the Bubba2 off.
"What should I do?" is my simple question.
/pelle