Yesterday we were hacked via the socks port (1080) used by Wingate. There were 3 sets of IP ranges that made it inside and were trying to send out spam. Luckily Symantec Enterprise AV stopped it. I blackholed the IP ranges for the attackers and the mayhem has stopped for now.
But at this point i am still unsure how the attackers made it inside. How would i determine this? Every attack was on the external adapter of the Wingate machine and all were directed to port 1080. The firewall settings were fairly brief and i saw no more settings to tweak there.
How does Wingate use port 1080? Can i block it altogether if my service ports are mapped (25, 80, 110 etc.)?
Anyone who has to deal with this type of exploit please lend me your observations. I am new to Wingate, so i am still getting used to the ways of a proxy server.
Thanks,
Matt