ZyXEL have published a security advisory which covers some of the ZyXEL routers we have provided our customers, the DX3301 and VMG3927.
New firmware has been released. Customers can either load this manually, or use the 'Upgrade Firmware' button found on the router information page on our Control Pages.
We have received further clarification that the vulnerabilities affect the router's web interface when exposed to the internet. Routers we configure for customers will have the web interface only allowable from our office IP range, and so this vulnerability is deemed low risk. We still recommend that customers upgrade. The upgrade process will take a few minutes but it does not reset the configuration.
We will make direct contact with customers with these routers, and support staff will mention this if and when they are talking to customers and notice the firmware is out of date.
Over the past week we have seen a huge number of 'bots' trying to guess customer email credentials in order to try to send email through our outbound email servers: smtp.aa.net.uk.
The attempts were being blocked due to wrong passwords being used, but this caused significant load on our severs due to all the database lookups involved. To address this, we are blocking IP addresses that are listed on the Spamhaus 'Exploits Blocklist (XBL)' and the Spamhaus 'Combined Spam Sources (CSS)' lists. -These are typically IP address known to have hijacked in some way or known spam senders.
This has reduced the load on the email servers significantly, however we are are still blocking around 1.5 million unique IP addresses each day.
We have had a small number of legitimate customers affected by this as their IP address is on these blocklists. (IPs can be looked up on https://check.spamhaus.org). In these cases, please do contact support and we can discuss workarounds.
This notification is for customers who run their own authoritative DNS servers and use our secondary-dns.co.uk as secondary (slave).
As part of our DNS infrastructure project we will start to initiate Zone Transfers from an additional set of IP addresses.
You will still send your NOTIFY to secondary-dns.co.uk but you will start to see AXFR requests from an additional set of IP addresses.
Therefore, please update your ACLs to allow the following addresses in addition to what you have at the moment:
Please update your ACLs by March 11th.
We will have an overlap of using the existing DNS servers and the new DNS servers. As part of our testing we will start to use the new IP addresses from February 17th