Jump to content

Recommended Posts

Posted

I've just had an email from Virgin stating "Our investigations have highlighted the below vulnerabilities / malware on your network. Please view the attachment for additional information."

 

"open dns resolver - (vulnerable service)"

 

I've port scanned our network externally and yes port 53 is open, however I have no port forwards for that port on Smoothwall to any internal devices

 

Has something changed with the latest Smoothwall ? Or is it something else ? Only thing we've changed recently is hosting the school website but wordfence is reporting that as okay.

Posted (edited)

Hi,

 

If you're using Smoothwall as your firewall check your "Smoothwall access" rules and "Firewall Rules" for any that might be permitting external access to DNS services (TCP/UDP port 53).

 

Regards,

Chris

 

P.s Amended with *external* access - you will likely see rules permitting access on your internal interfaces but you'll need those if you use the DNS forwarders internally.

Edited by Securly_Chris
Clarification
Posted

Yes, you'll want to go through and review all those rules to see if they're still needed.

 

At a glance, 2,3 and 6 permit various Smoothwall services to be accessed over the Internet so should be removed or locked down.

Posted (edited)

Must've been when the new firewall interface was introduced, by the looks of things it's enabled all the rules where I was sure some of those were disabled previously. I'll just disable them and see what happens :) cheers

 

*edit*

 

Disabling them has fixed it thanks again.

Edited by caffrey

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...