Slashdot Mirror


Most Home Routers Vulnerable to Flash UPnP Attack

An Anonymous reader noted that some folks at GNU Citizen have been researching UPNP Vulnerabilities in home routers, and have produced a flash swf file capable of opening open ports into your network simply by visiting an unfortunate URL. Looks like Firefox & Safari users are safe for now.

12 of 253 comments (clear)

  1. Turn off UPNP by russ1337 · · Score: 5, Insightful

    I thought the recommended steps for setting up a router were:

    A. Unbox
    B. Throw away the disk
    C. Plug in your machine, Turn on the router and navigate to the webgui
    D. Turn off UPNP
    E. ??? (Change default name and password, set WPA, Turn off SSID etc....)
    F. Profit...

    The point is, I'd always been told to turn off UPNP 'cos sooner or later something is going to open ports that you don't know about.

    1. Re:Turn off UPNP by Corporate+Troll · · Score: 3, Insightful

      Change default name and password, set WPA, Turn off SSID etc....

      I'm okay with all of that. The only thing I never get is why to turn off the SSID broadcast. If it's well secured, it doesn't matter if they know it's there or not. Besides, I'm pretty sure that just listening to traffic will reveal the presence of a wireless network.

    2. Re:Turn off UPNP by MBGMorden · · Score: 3, Insightful

      The other funny thing is that he claims to be "completely crashing a router so it resets to factory defaults". Now most of them, do that after a firmware update (but you have to already have admin access for that, so no glory there), or if you do a a hardware reset, in which case you no physical access to the device. I have NEVER heard of any router that will reboot with factory default settings if it crashes (and believe me, my first D-Link router several years ago crashed on a near daily basis - the poor little processor inside of it couldn't keep up with the number of connections my P2P software was making).

      --
      "People who think they know everything are very annoying to those of us who do."-Mark Twain
    3. Re:Turn off UPNP by KevReedUK · · Score: 3, Insightful

      planting a bush in your front yard that obscures a direct view of your front door

      From a security perspective, I would never want one of these as, if someone were at my front door trying to pick the lock, they would be obscured from view. I find living in a neighbourhood where there is the appearance that all the neighbours are nosy is far more effective as a form of security.
      --
      Just my $0.03 (At current exchange rates, my £0.02 is worth more than your $0.02)
  2. Open WiFi + this = trouble? by eknagy · · Score: 3, Insightful

    This will take an old-new argument to "to free or not to free my wifi" questions.

  3. Turn off UPnP! by ledow · · Score: 4, Insightful

    Turn off UPnP! Why on Earth do you want it on anyway? That's the problem here - an XSS is one matter, although being able to send SOAP-style requests across your local network is a major concern. But having a router that automatically opens ports based on virtually zero authentication? A nightmare waiting to happen.

    Never used it. Never wanted it. Never turned it on. Always turned it off on EVERYTHING. UPnP is the problem here - a simple (unauthenticated) HTTP-style page requested in a browser suddenly starts opening ports to your network. It should not happen. Even my DSL router/wireless router/Linux router has SSL only, passworded access to do anything even approaching opening ports. And if a webpage pops up with an authentication dialog with the header "Wireless Router" and you type in your password, then you're a fool, unless you specifically requested the router's configuration page.

    There's rarely even a log of what UPnP has done - which ports it's opened in the past etc. for whom.

    Just turn the damn thing off. It's too dangerous.

    1. Re:Turn off UPnP! by slim · · Score: 5, Insightful

      The thing is, it's just so damn useful. For a TCP/IP savvy person, setting up, say, a Bittorrent client, or Xbox Live online play without UPnP is a chore. For normal people, it's voodoo. With UPnP (and the right client) it Just Works. Convenient or secure... guess what most people will choose?

      But, agreed, it's scary stuff, if you believe your router ought to be a firewall. What's really needed is for home routers to start implementing authenticated UPnP, and for clients to work with it. (I must admit I've only glanced at the UPnP specs, but I seem to recall seeing references to an authenticated flavour).

  4. Re:Nothing new, really by Lumpy · · Score: 5, Insightful

    Yup, I have seen people computers infected from msn.com the banner ad's were at one time installing spyware from the default IE home page.

    All it takes is to get your nastyness in a bunch of Ad rotations from doubleclick and other scumbag webad companies and you can hose a huge swath of the net.

    --
    Do not look at laser with remaining good eye.
  5. Re:Nothing new, really by Nullav · · Score: 4, Insightful

    Yes, but the social engineering requirement is more or less gone in this case. It takes substantially less work to convince someone to click a link than to download a file. (Granted, Bonzai Buddy got people by just being a purple ape.)
    Why, look no further than the MyMiniCity/Goatse/2girls1cup links being posted here in every thread! At least one person clicks and ends up warning others. (Either by downmodding or posting.) Why, you just need someone who's curious enough to click.

    On the other hand, it requires a bit of work to get someone familiar with malware to click on a 'you just won' banner and download the mystery prize. Don't even get me started on random email attachments following nonsense messages.

    --
    I just read Slashdot for the articles.
  6. Re:Nothing new, really by eat+here_get+gas · · Score: 3, Insightful

    Firefox with AdBlock+, EasyElement, EasyList, SpyBot S&D, SpywareBlaster, disable Flash and UPnP, SMC Barricade 7004VBR (w NAT and firewall)...what's the problem? I've been running this for several years with no infections.
    99.9% of the shiit that gets blocked by these programs I don't need/want/miss anyway.

    --
    the significance of a signature is insignificant
  7. Re:Nothing new, really by cheater512 · · Score: 4, Insightful

    I use Linux with Seamonkey and..... uuhhh nothing else.
    No infections either. :)

    It looks like your doing everything except the simplest solution.

    Oh and yes I use UPNP.

  8. Re:Nothing new, really by Cal+Paterson · · Score: 3, Insightful

    Firefox with AdBlock+, EasyElement, EasyList, SpyBot S&D, SpywareBlaster, disable Flash and UPnP, SMC Barricade 7004VBR (w NAT and firewall)...what's the problem?
    That none of this is default?