Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » UPnP strikes again
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Is it safe to use an open DNS rather than your ISP's DNS? »
« GRC.com under attack?  
AuthorAll Replies

Jomsviking

join:2007-12-28

reply to swhx7
Re: UPnP strikes again

Due to the many questions and wrong interpretations of their discoveries, GNUCitizen has added an FAQ about this topic:

»www.gnucitizen.org/blog/flash-up···tack-faq

Interesting to note that Petkov himself, in the discussion following the FAQ, states:

"Many of you say that it is ok to turn UPnP off. Well, I am not sure about that. As a security guy I recommend turning UPnP off. Though, I can clearly see how this can turn into a problem. People does use it. Go explain to our grandma how to add a portforward through the admin interface so that she is secure when using whatever program she might have in mind. She would rather leave that decision to the computer, I guess. So let’s not be ignorant."

UPnP takes a blow, that is for sure, but most people won't even know about this problem. And even for those who know, fixing a static IP and doing port forwarding manually may be difficult and pose a number of problems. Instant Messaging/VOIP functionality going to hell, for example.

[Skype does NAT-traversality, but not specifically through an UPnP implementation, so it will, in principle, still work if you disable UPnP in your router]

Those who think that they can disable flash (ex: use of the NoScript add-on for Firefox) and keep UPnP on will have two problems at least:
- this hack might prove doable with Java or other web technologies. Just a matter of time, probably.
- Even if we block flash by default, we always have to allow it sometime in some sites we see as trusted; but those sites can be compromised without our knowledge and then...
And more and more sites are requiring this [crap] dynamical content to be displayed in order to function properly.

Either coders of web content plattforms start becoming security conscious [no way in hell that will happen] or UPnP implementation is changed to provide strong authentication measures, which will not be happening anytime soon....

So meanwhile we have a problem in our hands of convenience x security, which is not necessarily trivial.


Millenniumle

join:2007-11-11
Fredonia, NY
My Vonage router works fine behind another router that has UPnP disabled. Nothing needed to be setup. Just plug it in and go. Perhaps Vonage equipment checks the system for calls rather than relying on a notification of a call from the system.


NoUPNP

@cox.net

quote:
My Vonage router works fine behind another router that has UPnP disabled.
Same for my AT&T CallVantage router. In fact my router does not have uPnP on it at all. It isn't hard to do the application (VoIP in this case) correctly and not require uPnP or other security breaking hacks.
Forums » Up and Running » Security » SecurityIs it safe to use an open DNS rather than your ISP's DNS? »
« GRC.com under attack?  


Friday, 27-Nov 18:21:03 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [119] Time Warner Cable Fires Broadside At Broadcasters
· [111] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [68] In-Flight Internet Headed For Bumpy Landing?
· [60] Thanksgiving Open Thread
· [57] Verizon CEO: Hulu Will Be Dead Soon
· [38] EFF Wages War On Fine Print
· [38] ICANN Slams DNS Redirection
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· [Vista] Why is HD So Full? [Microsoft Help]
· Leveling to 85 [World of Warcraft]
· 5 hour energy for diabetic [General Questions]
· Bell offering 175M service :) [TekSavvy]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Whats the big deal about being "Old School"....? [World of Warcraft]