From time to time our FortiGate is logging botnet activity. When I look
at the lines in our syslog server the traffic is listed as incoming from
external hosts into our servers in DMZ. The lines show attempts to
install and execute a script in e.g. /...