Hi
Firstly, I am from South Africa.
I recently had to format and reload my wingate server, since then I have noticed strange IP's using my server to browse the web.
A whois puts them all in America.
I have been blackholeing them as I notice them but obviously there is some big security flaw in my setup.
Can someone help me fix this please?
Thank You
Sean
My firewall info on some of them.
Wingate firewall hit report:
Time: 2010/03/26 08:23:43 AM
Reason: Blackholed
Source MAC address: 00-26-0B-6C-2A-8C
Destination MAC address: 00-21-91-92-AF-3F
Source IP Address: 71.6.232.131 : 53653
Destination IP Address: "my proxy servers internal ip address" : 80
Protocol: TCP
TCP flags: S
Time-to-live: 43
Wingate firewall hit report:
Time: 2010/03/26 08:23:42 AM
Reason: Blackholed
Source MAC address: 00-26-0B-6C-2A-8C
Destination MAC address: 00-21-91-92-AF-3F
Source IP Address: 173.224.112.96 : 49857
Destination IP Address: "my proxy servers internal ip address" : 80
Protocol: TCP
TCP flags: S
Time-to-live: 44
Wingate firewall hit report:
Time: 2010/03/25 11:04:41 PM
Reason: Blackholed
Source MAC address: 00-26-0B-6C-2A-8C
Destination MAC address: 00-21-91-92-AF-3F
Source IP Address: 64.191.101.5 : 42333
Destination IP Address: "my proxy servers internal ip address" : 80
Protocol: TCP
TCP flags: S
Time-to-live: 52