|
|
 |
01-29-2013, 04:45 PM
|
#1
|
|
Platinum Member
Join Date: Sep 2008
Posts: 2,966
|
Researchers Find Serious Security Flaws in Universal Plug and Play
|
|
|
01-30-2013, 09:28 AM
|
#2
|
|
Diamond Member
Join Date: Oct 1999
Posts: 4,986
|
Hmm, UPnP has been a huge security problem since it was introduced, but the fact that its accessible/exploitable from the public internet is astonishing. I wonder how many routers will respond to UPnP commands, even when UPnP is 'disabled'. Some routers sill respond to WPS even when its 'disabled'.
|
|
|
01-30-2013, 03:52 PM
|
#3
|
|
Lifer
Join Date: Aug 2001
Posts: 22,234
|
Wow, I wonder if the UPnP code used by Tomato and DD-WRT is vulnerable or not? At least, if it is, it's sure to be fixed fairly quickly.
__________________
Rig(s) not listed, because I change computers, like some people change their socks.
|
|
|
01-30-2013, 05:06 PM
|
#4
|
|
Lifer
Join Date: May 2002
Location: Steeler Nation
Posts: 11,686
|
hmm... tool to detect if your UPnP is affected requires another affected software...
Cant say im inclined to install Java just to run this tool.
__________________
Quote:
Originally posted by: Eaglekeeper
Most anyone in the US that grew up in the city/inner city does not have the skills/knowledge to properly survive off the land.
Originally posted by: Dank69
It's (expletive deleted) easy. Throw seeds on the ground. Plants sprout. Pick hamburgers. Repeat.
|
|
|
|
01-30-2013, 06:43 PM
|
#5
|
|
Diamond Member
Join Date: Oct 1999
Posts: 7,599
|
|
|
|
01-31-2013, 09:06 AM
|
#6
|
|
Golden Member
Join Date: Apr 2012
Posts: 1,387
|
Quote:
Originally Posted by VirtualLarry
Wow, I wonder if the UPnP code used by Tomato and DD-WRT is vulnerable or not? At least, if it is, it's sure to be fixed fairly quickly.
|
Mini-UPnP is supposedly safer from version 1.4 on.
1.0 release has been the main culprit, and is probably on both those distributions.
As long as you don't run the UPnP on the external interface, you should be safe though.
|
|
|
02-10-2013, 02:49 PM
|
#7
|
|
Super Moderator Elite Member
Join Date: Oct 1999
Posts: 30,566
|
Here's a list (undoubtedly not definitive) of more affected routers and devices:
http://blog.defensecode.com/2013/02/...ory-cisco.html
Tons of brands listed there, skim down for yours.
On a similar note, D-Link has some routers that are vulnerable to rooting and code execution by unauthenticated attackers. More info here: http://news.softpedia.com/news/Vulne...e-327246.shtml
Quote:
|
D-Link has been notified of the problem, but the company doesn’t plan on doing anything about it, arguing that “this is a security problem from the user and/or browser.”
|
Wow. Guess I know one brand to never consider buying...
|
|
|
02-10-2013, 08:40 PM
|
#8
|
|
Junior Member
Join Date: Feb 2013
Posts: 12
|
Google grc shields up. The site has the ability to check your UPnP router vulnerability. No download required.
|
|
|
02-11-2013, 03:50 PM
|
#9
|
|
Diamond Member
Join Date: Jun 2008
Posts: 3,865
|
Quote:
Originally Posted by redbleed
Google grc shields up. The site has the ability to check your UPnP router vulnerability. No download required.
|
I went to that site since I last used to to check for open ports on a Vista Firewall behind a Netgear router and it showed up clean....
It might be because I went through the router settings and made sure to turn off things that I didn't need. UPnP might have been one of then.
I also have the UPnP service set to disabled as well.
|
|
|
02-18-2013, 05:24 PM
|
#10
|
|
Golden Member
Join Date: May 2003
Posts: 1,906
|
Quote:
Originally Posted by VirtualLarry
Wow, I wonder if the UPnP code used by Tomato and DD-WRT is vulnerable or not? At least, if it is, it's sure to be fixed fairly quickly.
|
It looks like most open source implementations are affected. There's a thread on the DD-WRT forum about it. I don't know about tomato but I don't think it will be patched for the freely distributed dd-wrt very soon.
__________________
"Your heart is in the right place. But still, you are a very disturbed individual."
-Xionide
|
|
|
02-21-2013, 07:48 PM
|
#11
|
|
Lifer
Join Date: Nov 2001
Location: Tucson, AZ
Posts: 11,252
|
Rapid7's scan said my Tomato USB router is protected.
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 09:09 AM.
|