Drunkard's Walk Forums

Full Version: UPNP problems
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hey everyone, I'm not sure how many of you have heard about this from other sources, but I'm posting this in the hopes that it'll prevent a few problems for some of you.

Short Story: turn of UPNP, now. *seriously*

Long Story:
UPNP (aka universal plug and play) is a communication protocol designed to make it easier for all the devices on the local network (your xbox/ps3/computer/whatever) to negotiate with the router about what ports they need open so things just work (meaning you don't have to worry that your favorite FPS wants ports 27000 - 27015 open, and that minecraft wants 25565).

This is generally seen as an improvement by users, and a security nightmare by network administrators. But because this was only supposed to be functional from in a private network (aka only devices located locally), no one raised that large of a fuss and life moved on.

But last week several security researchers found out some very worrying news. A significant percentage of routers were responding to UPNP requests from the public internet. Meaning that malicious entities can just tell your router to let them in.
What is a significant percentage you ask, try 81 Million (2.2% of the internet).

What is worse is that 20% (~16 million) of these can be exploited by one (1) udp packet.
Given the fact that there are 8 vulnerabilities discovered in how these routers deal with UPNP, I strongly believe that the percentage will only rise.

So what can you do?
Log into your router, and turn off UPNP.

If you want to make sure that UPNP is turned off Steve Gibson has added UPNP detection to his Shields Up tool (link).
Cisco has also released a document specifying what models of Cisco/Linksys routers are vulnerable (link)
If you want the to read all the gritty details, the can be found here (pdf)
This was also covered on Security Now, if you want to listen to a 1.5 hour discussion about all of this (youtu.be/wEa43qM4JjQ, you can skip ahead to the 9:45 mark)

Edit: and now I can't figure out how to post just a link to youtube *grumble*
-Terry
-----
"so listen up boy, or pornography starring your mother will be the second worst thing to happen to you today"
TF2: Spy
As a side note, it appears that you can embed the youtube links, but only with the WYSIWYG editor, and using the button it provides.  (Got into a conversatyion on yuku's help forum on the topic.)
Youtube link.
-----
Stand between the Silver Crystal and the Golden Sea.
"Youngsters these days just have no appreciation for the magnificence of the legendary cucumber."  --Krityan Elder, Tales of Vesperia.
Went to take care of this and found that "straight from the box" a couple years ago had the whole magilla off as a default, so. Big Grin
''We don't just borrow words; on occasion, English has pursued other languages down alleyways to beat
them unconscious and rifle their pockets for new vocabulary.''

-- James Nicoll
Although it's come up recently this isn't really news -- I remember warnings and advice about this issue going up on the Net years ago. Steve Gibson even had a little utility which told you if you were at risk, IIRC.
-- Bob
---------
Then the horns kicked in...
...and my shoes began to squeak.
Yah, UPNP was an issue a few years ago too. I think that was due to some virus/malware writers using it to spread infections between machines. AKA, one machine in the network gets infected, and then tells the router to open the flood gates so that other machines can be infected as well.

But this is the first I had heard of it being breached from the outside >.
-Terry
-----
"so listen up boy, or pornography starring your mother will be the second worst thing to happen to you today"
TF2: Spy