UPnP has been a security risk for years, but now it’s WORSE! — Psinergy LLC
X
Menu

UPnP has been a security risk for years, but now it’s WORSE!

UPnP (Universal Plug and Play) is intended to allow devices inside your local network to open needed ports in your modem/router. This was already an issue as viruses/malware could make a request to have the ports opened and allow malicious communication to go through unfettered. It isn’t supposed to accept instructions from outside the network (the WAN side), but a vulnerability that has been known since at least 2013 has been used to expand the exploit.

A new attack has emerged that is specifically designed to open your network to attack and to get into connected devices. EternalSilence, as it has been dubbed, not only compromises your router, but also opens ports on your device (computer, cell phones, smart devices, etc), and this attack appears to be related to the leaked NSA exploits EternalBlue and EternalRed. This is a pretty nasty exploit, to be honest.

 

How to tell if you’ve been compromised

It can be difficult to tell if you have been compromised by this specific exploit. One way that may indicate that you’ve been compromised is if you go into your router and you notice some “odd” ports that are open in UPnP, though even if you are compromised, this isn’t a true fire way of telling (because the ports are often released quickly after they are no longer used). The best thing to do for this is to honestly just do the fix below, whether you have been compromised or not.

 

How to Fix

  1. If you’ve been compromised, you need to do a factory reset of your router and disable UPnP completely.
    • You also need to scan all of your devices to make sure they haven’t been infected through this vulnerability.
  2. To help make sure you aren’t vulnerable for this exploit, make sure your router firmware is up-to-date, or purchase new up-to-date hardware.
    • and Make sure to turn OFF UPnP!
  3. If you’re not sure how to do this, we can help. Give us a call us at 612-234-7237. We will check the router to ensure UPnP is turned off (or turn it off if it’s not) remotely, in most cases, as a “Quick Fix“, or the “In-depth Remote Help” we will also apply needed router firmware updates (if none are needed, it would only be a Quick Fix). The scanning of your devices would not be part of the quick fix or the in-depth remote help service. In some cases, we may actually need you to bring in the device or schedule an onsite service, and we may recommend certain security appliances if that’s of a concern for your unique setup.

 


To read more in-depth about this attack, go to the Ars Technica article here.

 


 

The post UPnP has been a security risk for years, but now it’s WORSE! appeared first on Psinergy Tech.

You Might Also Liked

VLC Media Player Security Flaw! Change your Facebook password now! Severe RCE Flaw Disclosed in Popular LibreOffice and OpenOffice Software — The Hacker News Caribou Coffee Stores Hacked for months… but what about your business? Microsoft Issues Emergency Patch for Windows 7 – 10, including Server OS Avast had a glitch! – “DNS server isn’t responding” Unpatched MS Word Flaw Could Allow Hackers to Infect Your Computer — The Hacker News Tips for Success with Build 1803

Upcoming Events

Jul
2
Tue
11:55 am Total Solar Eclipse
Total Solar Eclipse
Jul 2 @ 11:55 am – 4:50 pm
A total solar eclipse occurs when the moon completely blocks the Sun, revealing the Sun’s beautiful outer atmosphere known as the corona. The path of totality will only be visible in parts of the southern pacific Ocean, central Chile, and central Argentina. When it makes landfall, it’s going to zip[...]
Jul
9
Tue
all-day Mercury Retrograde Begins
Mercury Retrograde Begins
Jul 9 all-day
see http://cantonbecker.com/retrograde for details…Click to print (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on LinkedIn (Opens in new window)Click to share on Twitter (Opens in new window)MoreClick to share on Reddit (Opens in new window)Click to share on Pocket (Opens in new window)Click[...]
all-day Saturn at Opposition
Saturn at Opposition
Jul 9 all-day
Saturn rules the summer sky, but on this night, the ringed planet truly takes center stage. When it reaches opposition (its closest approach to the Earth), Saturn will be bright and fully illuminated by the Sun. You may even notice that its rings look brighter than usual thanks to a[...]
Jul
13
Sat
10:00 am Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
Jul 13 @ 10:00 am – 6:00 pm
Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
An Apothecary of Light class These simple treatments from Esogetics Colorpuncture are designed for health maintenance and self-help with common complaints from a natural health viewpoint. The therapies learned in this module are for everybody, be it at home or on the road. We are offering this workshop for health-conscious[...]
Jul
28
Sun
all-day Delta Aquarids Meteor Shower
Delta Aquarids Meteor Shower
Jul 28 all-day
The Delta Aquarids is an average shower that can produce up to 20 meteors per hour at its peak. It is produced by debris left behind by comets Marsden and Kracht. The shower runs annually from July 12 to August 23. It peaks this year on the night of July[...]
Jul
31
Wed
all-day Mercury Retrograde Ends
Mercury Retrograde Ends
Jul 31 all-day
see http://cantonbecker.com/retrograde for details…Click to print (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on LinkedIn (Opens in new window)Click to share on Twitter (Opens in new window)MoreClick to share on Reddit (Opens in new window)Click to share on Pocket (Opens in new window)Click[...]
Aug
10
Sat
10:00 am Intro to Esogetics Crystal Thera... @ Psinergy Natural Health & Holistic Wellness
Intro to Esogetics Crystal Thera... @ Psinergy Natural Health & Holistic Wellness
Aug 10 @ 10:00 am – 6:00 pm
Intro to Esogetics Crystal Therapies @ Psinergy Natural Health & Holistic Wellness
An Apothecary of Light class These simple treatments from Esogetics Crystal Therapies are designed for health maintenance and self-help with common complaints from a natural health viewpoint. The therapies learned in this module are for everybody, be it at home or on the road. We are offering this workshop for health-conscious[...]
Aug
12
Mon
all-day Perseids Meteor Shower
Perseids Meteor Shower
Aug 12 all-day
The Perseids is one of the best meteor showers to observe, producing up to 60 meteors per hour at its peak. It is produced by comet Swift-Tuttle, which was discovered in 1862. The Perseids are famous for producing a large number of bright meteors. The shower runs annually from July[...]
Sep
5
Thu
6:00 pm Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Sep 5 @ 6:00 pm – 9:00 pm
Signals of the Body & Activating Dreams for Healing @ Psinergy Natural Health & Holistic Wellness
Learn 21+ Holistic self-care therapies that use a combination of touch and a special blend of essential oils and light to clear blockages and help promote health and wellbeing in this 1/2 day workshop. Therapies include body zones to promote dreaming, release emotional polarities and promoting emotional balance and areas to[...]
Sep
23
Mon
2:50 am Autumnal Equinox (Fall)
Autumnal Equinox (Fall)
Sep 23 @ 2:50 am – 3:50 am
The Sun will beam down directly on the equator giving us just about equal amounts of day and night in most parts of the world. If you live south of the equator, this is your Spring Equinox. Also, try balancing an egg on its end! Whether or not you succeed[...]