Slashdot Mirror


Most Home Routers Vulnerable to Flash UPnP Attack

An Anonymous reader noted that some folks at GNU Citizen have been researching UPNP Vulnerabilities in home routers, and have produced a flash swf file capable of opening open ports into your network simply by visiting an unfortunate URL. Looks like Firefox & Safari users are safe for now.

3 of 253 comments (clear)

  1. Turn off UPNP by russ1337 · · Score: 5, Insightful

    I thought the recommended steps for setting up a router were:

    A. Unbox
    B. Throw away the disk
    C. Plug in your machine, Turn on the router and navigate to the webgui
    D. Turn off UPNP
    E. ??? (Change default name and password, set WPA, Turn off SSID etc....)
    F. Profit...

    The point is, I'd always been told to turn off UPNP 'cos sooner or later something is going to open ports that you don't know about.

  2. Re:Turn off UPnP! by slim · · Score: 5, Insightful

    The thing is, it's just so damn useful. For a TCP/IP savvy person, setting up, say, a Bittorrent client, or Xbox Live online play without UPnP is a chore. For normal people, it's voodoo. With UPnP (and the right client) it Just Works. Convenient or secure... guess what most people will choose?

    But, agreed, it's scary stuff, if you believe your router ought to be a firewall. What's really needed is for home routers to start implementing authenticated UPnP, and for clients to work with it. (I must admit I've only glanced at the UPnP specs, but I seem to recall seeing references to an authenticated flavour).

  3. Re:Nothing new, really by Lumpy · · Score: 5, Insightful

    Yup, I have seen people computers infected from msn.com the banner ad's were at one time installing spyware from the default IE home page.

    All it takes is to get your nastyness in a bunch of Ad rotations from doubleclick and other scumbag webad companies and you can hose a huge swath of the net.

    --
    Do not look at laser with remaining good eye.