UPnP has been a security risk for years, but now it’s WORSE! — Psinergy LLC
X
Menu

UPnP has been a security risk for years, but now it’s WORSE!

UPnP (Universal Plug and Play) is intended to allow devices inside your local network to open needed ports in your modem/router. This was already an issue as viruses/malware could make a request to have the ports opened and allow malicious communication to go through unfettered. It isn’t supposed to accept instructions from outside the network (the WAN side), but a vulnerability that has been known since at least 2013 has been used to expand the exploit.

A new attack has emerged that is specifically designed to open your network to attack and to get into connected devices. EternalSilence, as it has been dubbed, not only compromises your router, but also opens ports on your device (computer, cell phones, smart devices, etc), and this attack appears to be related to the leaked NSA exploits EternalBlue and EternalRed. This is a pretty nasty exploit, to be honest.

 

How to tell if you’ve been compromised

It can be difficult to tell if you have been compromised by this specific exploit. One way that may indicate that you’ve been compromised is if you go into your router and you notice some “odd” ports that are open in UPnP, though even if you are compromised, this isn’t a true fire way of telling (because the ports are often released quickly after they are no longer used). The best thing to do for this is to honestly just do the fix below, whether you have been compromised or not.

 

How to Fix

  1. If you’ve been compromised, you need to do a factory reset of your router and disable UPnP completely.
    • You also need to scan all of your devices to make sure they haven’t been infected through this vulnerability.
  2. To help make sure you aren’t vulnerable for this exploit, make sure your router firmware is up-to-date, or purchase new up-to-date hardware.
    • and Make sure to turn OFF UPnP!
  3. If you’re not sure how to do this, we can help. Give us a call us at 612-234-7237. We will check the router to ensure UPnP is turned off (or turn it off if it’s not) remotely, in most cases, as a “Quick Fix“, or the “In-depth Remote Help” we will also apply needed router firmware updates (if none are needed, it would only be a Quick Fix). The scanning of your devices would not be part of the quick fix or the in-depth remote help service. In some cases, we may actually need you to bring in the device or schedule an onsite service, and we may recommend certain security appliances if that’s of a concern for your unique setup.

 


To read more in-depth about this attack, go to the Ars Technica article here.

 


 

The post UPnP has been a security risk for years, but now it’s WORSE! appeared first on Psinergy Tech.

You Might Also Liked

Severe RCE Flaw Disclosed in Popular LibreOffice and OpenOffice Software — The Hacker News Caribou Coffee Stores Hacked for months… but what about your business? Microsoft Issues Emergency Patch for Windows 7 – 10, including Server OS Avast had a glitch! – “DNS server isn’t responding” Unpatched MS Word Flaw Could Allow Hackers to Infect Your Computer — The Hacker News Tips for Success with Build 1803 Security Vulnerabilities: Is it time for a new computer? You thought Con-Artist Spam calls were bad enough — Now there are Con-Artist Spam Texts…

Upcoming Events

Mar
6
Wed
all-day Mercury Retrograde Begins
Mercury Retrograde Begins
Mar 6 all-day
see http://cantonbecker.com/retrograde for details…Click to print (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on LinkedIn (Opens in new window)Click to share on Twitter (Opens in new window)MoreClick to share on Reddit (Opens in new window)Click to share on Pocket (Opens in new window)Click[...]
Mar
7
Thu
6:00 pm Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Mar 7 @ 6:00 pm – 9:00 pm
Signals of the Body & Activating Dreams for Healing @ Psinergy Natural Health & Holistic Wellness
Learn 21+ Holistic self-care therapies that use a combination of touch and a special blend of essential oils and light to clear blockages and help promote health and wellbeing in this 1/2 day workshop. Therapies include body zones to promote dreaming, release emotional polarities and promoting emotional balance and areas to[...]
Mar
20
Wed
4:58 pm Vernal Equinox (Spring)
Vernal Equinox (Spring)
Mar 20 @ 4:58 pm – 5:58 pm
The date (near March 21 in the northern hemisphere) when night and day are nearly the same length and Sun crosses the celestial equator (i.e., declination 0) moving northward. In the southern hemisphere, the vernal equinox corresponds to the center of the Sun crossing the celestial equator moving southward and[...]
Mar
28
Thu
all-day Mercury Retrograde Ends
Mercury Retrograde Ends
Mar 28 all-day
see http://cantonbecker.com/retrograde for details…Click to print (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on LinkedIn (Opens in new window)Click to share on Twitter (Opens in new window)MoreClick to share on Reddit (Opens in new window)Click to share on Pocket (Opens in new window)Click[...]
Apr
6
Sat
10:00 am Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
Apr 6 @ 10:00 am – 6:00 pm
Colorpuncture for Me and My Family @ Psinergy Natural Health & Holistic Wellness
An Apothecary of Light class These simple treatments from Esogetics Colorpuncture are designed for health maintenance and self-help with common complaints from a natural health viewpoint. The therapies learned in this module are for everybody, be it at home or on the road. We are offering this workshop for health-conscious[...]
Apr
22
Mon
all-day Lyrids Meteor Shower
Lyrids Meteor Shower
Apr 22 – Apr 23 all-day
The Lyrids is an average shower, usually producing about 20 meteors per hour at its peak. It is produced by dust particles left behind by comet C/1861 G1 Thatcher, which was discovered in 1861. The shower runs annually from April 16-25. It peaks this year on the night of the[...]
May
4
Sat
10:00 am Intro to Esogetics Crystal Thera... @ Psinergy Natural Health & Holistic Wellness
Intro to Esogetics Crystal Thera... @ Psinergy Natural Health & Holistic Wellness
May 4 @ 10:00 am – 6:00 pm
Intro to Esogetics Crystal Therapies @ Psinergy Natural Health & Holistic Wellness
An Apothecary of Light class These simple treatments from Esogetics Crystal Therapies are designed for health maintenance and self-help with common complaints from a natural health viewpoint. The therapies learned in this module are for everybody, be it at home or on the road. We are offering this workshop for health-conscious[...]
May
6
Mon
all-day Eta Aquarids Meteor Shower
Eta Aquarids Meteor Shower
May 6 – May 7 all-day
The Eta Aquarids is an above average shower, capable of producing up to 60 meteors per hour at its peak. Most of the activity is seen in the Southern Hemisphere. In the Northern Hemisphere, the rate can reach about 30 meteors per hour. It is produced by dust particles left[...]
Jun
10
Mon
all-day Jupiter at Opposition
Jupiter at Opposition
Jun 10 all-day
The giant planet will be at its closest approach to Earth and its face will be fully illuminated by the Sun. It will be brighter than any other time of the year and will be visible all night long. This is the best time to view and photograph Jupiter and[...]
Jun
12
Wed
6:00 pm Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Signals of the Body & Activating... @ Psinergy Natural Health & Holistic Wellness
Jun 12 @ 6:00 pm – 9:00 pm
Signals of the Body & Activating Dreams for Healing @ Psinergy Natural Health & Holistic Wellness
Learn 21+ Holistic self-care therapies that use a combination of touch and a special blend of essential oils and light to clear blockages and help promote health and wellbeing in this 1/2 day workshop. Therapies include body zones to promote dreaming, release emotional polarities and promoting emotional balance and areas to[...]