Dear All,
Just found out that some one is using my SME 5.5 Box (Update6) to line up a "DOS UDP echo+chargen bomb" attack to an IP,
They are comming from many different IP and via my SME 5.5 box change to an IP for dDos attack.
I have Snort+Guardian installed and can see the attack, but have not idea how to stop them. (Looks like Guardian are not stoping them, and if guardian stop they just change the IP.....)
At first I think SME is having quit a good security, but now, I am a little bit upset..... or may be I have do something wrong.......
Please help, as I do not want my SME server to attack any one on net......
Best Regards,
Paul T.C.Fung