![]() |
|
|
|
Registered
|
Security Flaws in Universal Plug and Play: Unplug, Don't Play
I have been following some of the recent exploits of UPnP for a couple of weeks now. The script kiddies have found easy ways of taking advantage of the vulns. They have realized that they can p0wn your Internet connection and possibly everything behind the router as well. Then, I saw this report that was released yesterday. The stats are amazing and scary.
We have all learned over the years to protect ourselves from malware and viruses. But, most people will install a home router and not think about it because they tend to just work. I have found that a high percentage of consumer-grade routers have UPnP enabled by default. Take a couple of minutes and read this link. https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play There is also a link to a Windows tool in the article that helps you to identify if you are vulnerable. There are also instructions for using Metasploit for Mac and Linux users. I recommend that you scan your devices whether they be something you purchased or something that your ISP has provided. (there are reports of some Verizon FIOS devices being vulnerable). If you run the scan and it reports that your equipment is vulnerable, don't panic. First, disable UPnP on your device. Then check with the vendor to see if they have any firmware updates for your device. ![]() |
||
![]() |
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,975
|
I saw that report too and surprised it was news. Since UPnP was cerated it was always exploitable. I guess the surprising thing is these vendors are allowing it on the WAN/internet interface....
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
![]() |
|
Too big to fail
|
I tried to run the scanner provided in the link, and I got an error "Registration Servers cannot be reached"
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs |
||
![]() |
|
Get off my lawn!
|
When I got to the point I HAD to give them my name, address, job title and email I said screw it. I don't need more junk mail for trying to run a FREE utility.
__________________
Glen 49 Year member of the Porsche Club of America 1985 911 Carrera; 2017 Macan 1986 El Camino with Fuel Injected 350 Crate Engine My Motto: I will never be too old to have a happy childhood! |
||
![]() |
|
Registered User
Join Date: Jan 2013
Posts: 1,724
|
What does all this mean in english? Is this a setting on the wifi router that needs turned off? I am leary of running a third party app on my computer that tells me I have security flaws.
|
||
![]() |
|
Did you get the memo?
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,300
|
+1 Can someone interpret the IT speak for the simpletons?
__________________
‘07 Mazda RX8-8 Past: 911T, 911SC, Carrera, 951s, 955, 996s, 987s, 986s, 997s, BMW 5x, C36, C63, XJR, S8, Maserati Coupe, GT500, etc |
||
![]() |
|
![]() |
Too big to fail
|
Quote:
At face value, this ScanNow tool from rapid7.com appears to be a thinly-veiled collector for sales leads and marketing data.
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs Last edited by widebody911; 01-30-2013 at 10:59 AM.. |
||
![]() |
|
Registered
|
My external router has upnp disabled, on my internal switch it's available. Upnp and most other types of traffic can't leave the DMZ to get to the broadband router.
__________________
2021 Model Y 2005 Cayenne Turbo 2012 Panamera 4S 1980 911 SC 1999 996 Cab |
||
![]() |
|
AutoBahned
|
go to Tools or setup or similar after you log in to your router
your router will be at 128.168.1.1 or similar - plug that into your browser Last edited by RWebb; 01-30-2013 at 04:09 PM.. |
||
![]() |
|
Burn the fire.
|
I've always disabled UPnP on my hardware and computers as early as possible. Exploits for UPnP have been around as long as UPnP has been around. Must have been implemented by the same guys who thought ActiveX controls with no security controls were a great idea.
__________________
[x] Working | [_] Broken: 2017 Victory Octane [x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi "Drive it like you stole it." |
||
![]() |
|
Registered
|
Quote:
|
||
![]() |
|
Too big to fail
|
The simplest solution is to redirect all traffic to 127.0.0.1
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs |
||
![]() |
|
Get off my lawn!
|
__________________
Glen 49 Year member of the Porsche Club of America 1985 911 Carrera; 2017 Macan 1986 El Camino with Fuel Injected 350 Crate Engine My Motto: I will never be too old to have a happy childhood! |
||
![]() |
|
Registered
|
It's generally whatever your gateway is set to. In Windows you can open a command prompt and type "ipconfig /all" and get that. On MAC you can go to a terminal window and use "netstat -nr"
__________________
2021 Model Y 2005 Cayenne Turbo 2012 Panamera 4S 1980 911 SC 1999 996 Cab |
||
![]() |
|
canna change law physics
|
That scan software requires JAVA to be installed. Nope....
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Registered
|
Quote:
![]() |
||
![]() |
|
AutoBahned
|
yes, 192.168....
thx Dave |
||
![]() |
|
Registered
Join Date: Oct 2006
Location: So-Cal
Posts: 428
|
You think UPnP is bad ............. Verizon installs WEP by default on all there FIOS installs
__________________
1987 Carrera |
||
![]() |
|
![]() |
Get off my lawn!
|
My router was at the standard 192.168.1.1 for years. One day the internet did not work. I shut down the cable modem and router and computer. Restart and all of a sudden I am at the new IP. I guess my cable provider changed their system.
__________________
Glen 49 Year member of the Porsche Club of America 1985 911 Carrera; 2017 Macan 1986 El Camino with Fuel Injected 350 Crate Engine My Motto: I will never be too old to have a happy childhood! |
||
![]() |
|