Hello,
After reading the following article at Arstechnica (https://arstechnica.com/information-technology/2022/03/unending-data-floods-and-complete-resource-exhaustion-ddoses-get-meaner/?comments=1&start=0), and then the University of Maryland page for the original research (https://geneva.cs.umd.edu/posts/usenix21-weaponizing-censors) I'm curious to know if some configuration of Sophos XG Firewall is susceptible to being leveraged as described to amplify DDoS attacks.
As a user of the home licensed Sophos XG, I'm grateful to Sophos for providing thier product for free. However, I want to be certain that I'm not inadvertently being used by bad actors to amplify DDoS attacks.
Is there some way that I can check for these behaviours in the logs, or is there a specific (mis)configuration that would put me at risk?
This thread was automatically locked due to age.