Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
Paul_Heery's Avatar
 
Join Date: Dec 2001
Location: Elsewhere, CT
Posts: 2,121
Garage
Security Flaws in Universal Plug and Play: Unplug, Don't Play

I have been following some of the recent exploits of UPnP for a couple of weeks now. The script kiddies have found easy ways of taking advantage of the vulns. They have realized that they can p0wn your Internet connection and possibly everything behind the router as well. Then, I saw this report that was released yesterday. The stats are amazing and scary.

We have all learned over the years to protect ourselves from malware and viruses. But, most people will install a home router and not think about it because they tend to just work. I have found that a high percentage of consumer-grade routers have UPnP enabled by default.

Take a couple of minutes and read this link.
https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play
There is also a link to a Windows tool in the article that helps you to identify if you are vulnerable. There are also instructions for using Metasploit for Mac and Linux users. I recommend that you scan your devices whether they be something you purchased or something that your ISP has provided. (there are reports of some Verizon FIOS devices being vulnerable).

If you run the scan and it reports that your equipment is vulnerable, don't panic. First, disable UPnP on your device. Then check with the vendor to see if they have any firmware updates for your device.


Old 01-30-2013, 04:06 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,975
I saw that report too and surprised it was news. Since UPnP was cerated it was always exploitable. I guess the surprising thing is these vendors are allowing it on the WAN/internet interface....
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 01-30-2013, 05:40 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Too big to fail
 
widebody911's Avatar
 
Join Date: Jan 2002
Location: Carmichael, CA
Posts: 33,894
Garage
Send a message via AIM to widebody911 Send a message via Yahoo to widebody911
I tried to run the scanner provided in the link, and I got an error "Registration Servers cannot be reached"
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had."
'03 E46 M3
'57 356A
Various VWs
Old 01-30-2013, 06:15 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 84,764
Garage
Quote:
Originally Posted by widebody911 View Post
I tried to run the scanner provided in the link, and I got an error "Registration Servers cannot be reached"
When I got to the point I HAD to give them my name, address, job title and email I said screw it. I don't need more junk mail for trying to run a FREE utility.
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 01-30-2013, 06:46 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Registered User
 
Aragorn's Avatar
 
Join Date: Jan 2013
Posts: 1,724
What does all this mean in english? Is this a setting on the wifi router that needs turned off? I am leary of running a third party app on my computer that tells me I have security flaws.
Old 01-30-2013, 09:16 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Did you get the memo?
 
onewhippedpuppy's Avatar
 
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,300
Quote:
Originally Posted by Aragorn View Post
What does all this mean in english? Is this a setting on the wifi router that needs turned off? I am leary of running a third party app on my computer that tells me I have security flaws.
+1 Can someone interpret the IT speak for the simpletons?
__________________
‘07 Mazda RX8-8
Past: 911T, 911SC, Carrera, 951s, 955, 996s, 987s, 986s, 997s, BMW 5x, C36, C63, XJR, S8, Maserati Coupe, GT500, etc
Old 01-30-2013, 10:47 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Too big to fail
 
widebody911's Avatar
 
Join Date: Jan 2002
Location: Carmichael, CA
Posts: 33,894
Garage
Send a message via AIM to widebody911 Send a message via Yahoo to widebody911
Quote:
Originally Posted by onewhippedpuppy View Post
+1 Can someone interpret the IT speak for the simpletons?
Basically devices which utilize UPnP to make installation and configuration easier of network devices (ie routers, cameras, etc) for the end user also contain security deficiencies which make them easy to exploit.

At face value, this ScanNow tool from rapid7.com appears to be a thinly-veiled collector for sales leads and marketing data.
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had."
'03 E46 M3
'57 356A
Various VWs

Last edited by widebody911; 01-30-2013 at 10:59 AM..
Old 01-30-2013, 10:54 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
Scott R's Avatar
 
Join Date: Feb 2001
Location: Aspen CO US
Posts: 16,054
Garage
My external router has upnp disabled, on my internal switch it's available. Upnp and most other types of traffic can't leave the DMZ to get to the broadband router.
__________________
2021 Model Y
2005 Cayenne Turbo
2012 Panamera 4S
1980 911 SC
1999 996 Cab
Old 01-30-2013, 11:58 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
go to Tools or setup or similar after you log in to your router

your router will be at 128.168.1.1 or similar - plug that into your browser

Last edited by RWebb; 01-30-2013 at 04:09 PM..
Old 01-30-2013, 01:05 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Burn the fire.
 
Brando's Avatar
 
Join Date: May 2003
Location: Land of Liberty, NH
Posts: 6,501
Garage
I've always disabled UPnP on my hardware and computers as early as possible. Exploits for UPnP have been around as long as UPnP has been around. Must have been implemented by the same guys who thought ActiveX controls with no security controls were a great idea.
__________________
[x] Working | [_] Broken: 2017 Victory Octane
[x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi

"Drive it like you stole it."
Old 01-30-2013, 04:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:


your router will be at 128.168.1.1 or similar - plug that into your browser
Correction - 192.168.1.1
Old 01-30-2013, 06:07 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Too big to fail
 
widebody911's Avatar
 
Join Date: Jan 2002
Location: Carmichael, CA
Posts: 33,894
Garage
Send a message via AIM to widebody911 Send a message via Yahoo to widebody911
The simplest solution is to redirect all traffic to 127.0.0.1
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had."
'03 E46 M3
'57 356A
Various VWs
Old 01-30-2013, 06:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 84,764
Garage
Quote:
Originally Posted by slodave View Post
Correction - 192.168.1.1
Mine is 10.0.1.1
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 01-30-2013, 07:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Registered
 
Scott R's Avatar
 
Join Date: Feb 2001
Location: Aspen CO US
Posts: 16,054
Garage
Quote:
Originally Posted by GH85Carrera View Post
Mine is 10.0.1.1
It's generally whatever your gateway is set to. In Windows you can open a command prompt and type "ipconfig /all" and get that. On MAC you can go to a terminal window and use "netstat -nr"
__________________
2021 Model Y
2005 Cayenne Turbo
2012 Panamera 4S
1980 911 SC
1999 996 Cab
Old 01-30-2013, 07:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
That scan software requires JAVA to be installed. Nope....
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 01-30-2013, 07:11 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:


Quote de slodave



Correction - 192.168.1.1


Mine is 10.0.1.1
That may be. But the first octet that Randy posted is wrong.
Old 01-30-2013, 07:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
AutoBahned
 
RWebb's Avatar
 
Join Date: Jul 2007
Location: Greater Metropolitan Nimrod, Orygun
Posts: 55,993
Garage
yes, 192.168....

thx Dave
Old 01-30-2013, 09:16 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
You think UPnP is bad ............. Verizon installs WEP by default on all there FIOS installs
__________________
1987 Carrera
Old 01-31-2013, 01:07 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
 
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 84,764
Garage
Quote:
Originally Posted by slodave View Post
That may be. But the first octet that Randy posted is wrong.
My router was at the standard 192.168.1.1 for years. One day the internet did not work. I shut down the cable modem and router and computer. Restart and all of a sudden I am at the new IP. I guess my cable provider changed their system.

__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 01-31-2013, 05:27 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Reply


 


All times are GMT -8. The time now is 01:36 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.