Router security - PNP

For system help, all hardware / software topics NOTE: use Coders Corner for all coders topics.

Moderators: Krom, Grendel

Post Reply
User avatar
thewolfe
DBB Admiral
DBB Admiral
Posts: 1987
Joined: Tue Nov 05, 2002 3:01 am
Contact:

Router security - PNP

Post by thewolfe »

I read that I should disable plug and play. I'm looking at settings. Is this it? Image
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: Router security - PNP

Post by Krom »

UPnP is just a system for automatic port forwarding in the event an application needs a listening port for something (like online games/im clients/vnc/P2P/etc). Disabling it won't really do anything for your security, but might make some features in various UPnP supporting applications stop working.
User avatar
thewolfe
DBB Admiral
DBB Admiral
Posts: 1987
Joined: Tue Nov 05, 2002 3:01 am
Contact:

Re: Router security - PNP

Post by thewolfe »

I'll have to get part of the transcript from the "security Now" program I was listening to and it's not up yet.
User avatar
thewolfe
DBB Admiral
DBB Admiral
Posts: 1987
Joined: Tue Nov 05, 2002 3:01 am
Contact:

Re: Router security - PNP

Post by thewolfe »

The info starts about half way down page 3 on this transcript. http://www.grc.com/sn/sn-315.pdf
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: Router security - PNP

Post by Krom »

If you follow through on the links and do your research you can see which devices are actually susceptible to a UPnP breach. You would be better served by updating the firmware on your device to a version that fixes the issue, or if the manufacturer has quit releasing security updates for it then you should buy a new router from someone that continues to support their products.

See the list of known buggy firmware devices here:
http://www.upnp-hacks.org/devices.html
User avatar
thewolfe
DBB Admiral
DBB Admiral
Posts: 1987
Joined: Tue Nov 05, 2002 3:01 am
Contact:

Re: Router security - PNP

Post by thewolfe »

Thanks Krom. I did see the router companies they were talking about but didn't know if there were other's.. Mine is not among them.
User avatar
Jeff250
DBB Master
DBB Master
Posts: 6539
Joined: Sun Sep 05, 1999 2:01 am
Location: ❄️❄️❄️

Re: Router security - PNP

Post by Jeff250 »

By the list's own admission, it is far from exhaustive.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: Router security - PNP

Post by Krom »

Also keep in mind that the list is old, and almost every device in the list has already been patched.
User avatar
Foil
DBB Material Defender
DBB Material Defender
Posts: 4900
Joined: Tue Nov 23, 2004 3:31 pm
Location: Denver, Colorado, USA
Contact:

Re: Router security - PNP

Post by Foil »

I've personally disabled UPnP on my router, only because my WHS v1 tries to periodically check/update the port-forwarding via UPnP, but I'd rather handle it myself.
Post Reply